CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-5373

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

    Published: 24 Jan 2017
    5.3
    Medium

    CVE-2017-0368

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw making rawHTML mode apply to system messages.

    Published: 24 Jan 2017
    7.8
    High

    CVE-2017-5618

    Last Modified: 20 Apr 2025

    GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.

    Published: 24 Jan 2017
    6.5
    Medium

    CVE-2017-2596

    Last Modified: 20 Apr 2025

    The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXON instruction, which allows KVM L1 guest OS users to cause a denial of service (host OS memory consumption) by leveraging the mishandling of page references.

    Published: 24 Jan 2017
    5.5
    Medium

    CVE-2017-2615

    Last Modified: 21 Nov 2024

    Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.

    Published: 24 Jan 2017
    5.3
    Medium

    CVE-2017-5383

    Last Modified: 25 Nov 2025

    URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

    Published: 24 Jan 2017
    8.8
    High

    CVE-2016-9012

    Last Modified: 20 Apr 2025

    CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2013-7452

    Last Modified: 20 Apr 2025

    The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-2242

    Last Modified: 20 Apr 2025

    Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2016-0765

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.

    Published: 23 Jan 2017
    7.8
    High

    CVE-2016-5720

    Last Modified: 20 Apr 2025

    Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) msi.dll, (2) dpapi.dll, or (3) cryptui.dll that is located in the current working directory.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2016-6160

    Last Modified: 20 Apr 2025

    tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to CVE-2017-14266.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2016-6601

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2016-6668

    Last Modified: 20 Apr 2025

    The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to obtain the secret key for communicating with HipChat instances by reading unspecified pages.

    Published: 23 Jan 2017
    7.8
    High

    CVE-2016-1281

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Trojan horse DLL in the "application directory", as demonstrated with the USP10.dll, RichEd20.dll, NTMarta.dll and SRClient.dll DLLs.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2013-7451

    Last Modified: 20 Apr 2025

    The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2013-7454

    Last Modified: 20 Apr 2025

    The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.

    Published: 23 Jan 2017
    8.8
    High

    CVE-2016-1417

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Snort 2.9.7.0-WIN32 allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse tcapi.dll that is located in the same folder on a remote file share as a pcap file that is being processed.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-2783

    Last Modified: 20 Apr 2025

    Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-6602

    Last Modified: 20 Apr 2025

    ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2013-7453

    Last Modified: 20 Apr 2025

    The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.

    Published: 23 Jan 2017
    6.5
    Medium

    CVE-2015-7743

    Last Modified: 20 Apr 2025

    XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2015-8861

    Last Modified: 20 Apr 2025

    The handlebars package before 4.0.0 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

    Published: 23 Jan 2017
    7.8
    High

    CVE-2015-8971

    Last Modified: 20 Apr 2025

    Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2016-4056

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Backend component in TYPO3 6.2.x before 6.2.19 allows remote attackers to inject arbitrary web script or HTML via the module parameter when creating a bookmark.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2014-8362

    Last Modified: 20 Apr 2025

    Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enabled interface.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2014-9772

    Last Modified: 20 Apr 2025

    The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2015-4626

    Last Modified: 20 Apr 2025

    B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative value in an overdraft.

    Published: 23 Jan 2017
    5.3
    Medium

    CVE-2015-8859

    Last Modified: 20 Apr 2025

    The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2015-8857

    Last Modified: 20 Apr 2025

    The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by leveraging improperly rewritten Javascript.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2015-8858

    Last Modified: 20 Apr 2025

    The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."

    Published: 23 Jan 2017
    7.5
    High

    CVE-2015-8854

    Last Modified: 20 Apr 2025

    The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2015-8856

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the serve-index package before 1.6.3 for Node.js allows remote attackers to inject arbitrary web script or HTML via a crafted file or directory name.

    Published: 23 Jan 2017
    6.1
    Medium

    CVE-2015-8862

    Last Modified: 20 Apr 2025

    mustache package before 2.2.1 for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging a template with an attribute that is not quoted.

    Published: 23 Jan 2017
    8.8
    High

    CVE-2016-0769

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow (1) remote administrators to execute arbitrary SQL commands via the delid parameter or remote authenticated users to execute arbitrary SQL commands via the (2) view, (3) mark, or (4) change parameter.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-1925

    Last Modified: 20 Apr 2025

    Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.

    Published: 23 Jan 2017
    8.8
    High

    CVE-2016-4340

    Last Modified: 20 Apr 2025

    The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

    Published: 23 Jan 2017
    8.1
    High

    CVE-2016-4338

    Last Modified: 20 Apr 2025

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2016-4793

    Last Modified: 20 Apr 2025

    The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

    Published: 23 Jan 2017
    8.1
    High

    CVE-2016-5091

    Last Modified: 20 Apr 2025

    Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.

    Published: 23 Jan 2017
    7.5
    High

    CVE-2016-5119

    Last Modified: 20 Apr 2025

    The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.

    Published: 23 Jan 2017
    4.8
    Medium

    CVE-2016-5237

    Last Modified: 20 Apr 2025

    Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files and possibly gain privileges as demonstrated by a Trojan horse Steam.exe file.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-5742

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the XML-RPC interface in Movable Type Pro and Advanced 6.x before 6.1.3 and 6.2.x before 6.2.6 and Movable Type Open Source 5.2.13 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-5873

    Last Modified: 20 Apr 2025

    Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.

    Published: 23 Jan 2017
    5.9
    Medium

    CVE-2016-5876

    Last Modified: 20 Apr 2025

    ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct request.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-6164

    Last Modified: 20 Apr 2025

    Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors involving sample size.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-6517

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp.

    Published: 23 Jan 2017
    8.8
    High

    CVE-2016-6521

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors.

    Published: 23 Jan 2017
    9.1
    Critical

    CVE-2016-6582

    Last Modified: 20 Apr 2025

    The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.

    Published: 23 Jan 2017
    9.8
    Critical

    CVE-2016-6600

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

    Published: 23 Jan 2017