Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-20
Total 9170 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-17159 1 Huawei 4 Mt8-emui4.1, Mt8-emui4.1 Firmware, Nts-al00 and 1 more 2018-03-14 6.1 MEDIUM 6.5 MEDIUM
Some Huawei smart phones with software of NXT-AL10C00B386, NXT-CL00C92B386, NXT-DL00C17B386, NXT-TL00C01B386SP01, NTS-AL00C00B535 have a DoS vulnerability due to insufficient input validation. An unauthenticated attacker could send malformed System Information(SI) messages to the smart phone within radio range by special wireless device. Successful exploit could make the smart phone restart.
CVE-2017-17201 1 Huawei 12 Berlin-emui5.0, Berlin-emui5.0 Firmware, Berlin-l21 and 9 more 2018-03-14 4.3 MEDIUM 5.5 MEDIUM
Some huawei smartphones with software BTV-DL09C233B350, Berlin-L21HNC432B360, Berlin-L22HNC636B360, Berlin-L24HNC567B360, Berlin-L21C10B130, Berlin-L21C185B132, Berlin-L21C464B130, Berlin-L22C346B140, Berlin-L22C636B160, Berlin-L23C605B131, Berlin-L23DOMC109B160, MHA-AL00AC00B125 have a DoS vulnerability. Due to insufficient input validation, an attacker could trick a user to execute a malicious application, which could be exploited by attacker to launch DoS attacks.
CVE-2017-6169 1 F5 1 Big-ip Policy Enforcement Manager 2018-03-13 4.3 MEDIUM 6.8 MEDIUM
In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Management Microkernel (TMM) to produce a core file when it receives malformed URLs during categorization.
CVE-2014-8420 1 Sonicwall 3 Analyzer, Global Management System, Uma Em5000 2018-03-12 9.0 HIGH N/A
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote authenticated users to execute arbitrary code via unspecified vectors.
CVE-2016-8530 1 Hp 1 Intelligent Management Center 2018-03-12 5.0 MEDIUM 7.5 HIGH
A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.
CVE-2017-15817 1 Google 1 Android 2018-03-12 9.3 HIGH 7.8 HIGH
In all Qualcomm products with Android releases from CAF using the Linux kernel, when an access point sends a challenge text greater than 128 bytes, the host driver is unable to validate this potentially leading to authentication failure.
CVE-2018-1298 1 Apache 1 Qpid Broker-j 2018-03-10 4.3 MEDIUM 5.9 MEDIUM
A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attacker to crash the broker instance. AMQP 1.0 and HTTP connections are not affected. An authentication of incoming AMQP connections in Apache Qpid Broker-J is performed by special entities called "Authentication Providers". Each Authentication Provider can support several SASL mechanisms which are offered to the connecting clients as part of SASL negotiation process. The client chooses the most appropriate SASL mechanism for authentication. Authentication Providers of following types supports PLAIN SASL mechanism: Plain, PlainPasswordFile, SimpleLDAP, Base64MD5PasswordFile, MD5, SCRAM-SHA-256, SCRAM-SHA-1. XOAUTH2 SASL mechanism is supported by Authentication Providers of type OAuth2. If an AMQP port is configured with any of these Authentication Providers, the Broker may be vulnerable.
CVE-2017-8976 1 Hp 1 Moonshot Provisioning Manager Appliance 2018-03-09 10.0 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8971 1 Hp 1 Matrix Operating Environment 2018-03-09 4.0 MEDIUM 4.3 MEDIUM
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-8972 1 Hp 1 Matrix Operating Environment 2018-03-09 4.0 MEDIUM 4.3 MEDIUM
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-17299 1 Huawei 32 Ar120-s, Ar120-s Firmware, Ar1200 and 29 more 2018-03-09 5.0 MEDIUM 7.5 HIGH
Huawei AR120-S V200R006C10, V200R007C00, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C02, AR1200-S V200R006C10, V200R007C00, V200R008C20, AR150 V200R006C10, V200R007C00, V200R007C02, AR150-S V200R006C10, V200R007C00, AR160 V200R006C10, V200R006C12, V200R007C00S, V200R007C02, AR200 V200R006C10, V200R007C00, AR200-S V200R006C10, V200R007C00, AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C02, AR2200-S V200R006C10, V200R007C00, V200R008C20, AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C02, AR3600 V200R006C10, V200R007C00, AR510 V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, IPS Module V500R001C30, NIP6300 V500R001C30, NetEngine16EX V200R006C10, V200R007C00 have an insufficient input validation vulnerability. An unauthenticated, remote attacker may send crafted IKE V2 messages to the affected products. Due to the insufficient validation of the messages, successful exploit will cause invalid memory access and result in a denial of service on the affected products.
CVE-2017-8977 1 Hp 1 Moonshot Provisioning Manager Appliance 2018-03-09 8.5 HIGH 9.1 CRITICAL
A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8975 1 Hp 1 Moonshot Provisioning Manager Appliance 2018-03-09 10.0 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8973 1 Hp 1 Matrix Operating Environment 2018-03-09 4.0 MEDIUM 4.3 MEDIUM
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-5808 1 Hp 1 Data Protector 2018-03-07 7.8 HIGH 7.5 HIGH
A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.
CVE-2017-5794 1 Hp 1 Intelligent Management Center 2018-03-07 9.0 HIGH 8.8 HIGH
A Remote Arbitrary File Download vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.
CVE-2017-5793 1 Hp 1 Intelligent Management Center 2018-03-07 9.0 HIGH 8.8 HIGH
A Remote Arbitrary Code Execution vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.
CVE-2017-8260 1 Google 1 Android 2018-03-06 6.8 MEDIUM 7.8 HIGH
In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.
CVE-2017-13229 1 Google 1 Android 2018-03-06 10.0 HIGH 9.8 CRITICAL
A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID: A-68160703.
CVE-2018-1000023 1 Insight.bitpay 1 Insight-api 2018-03-06 5.0 MEDIUM 5.3 MEDIUM
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.