Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-3523 | 1 Avast | 2 Avast Antivirus Home, Avast Antivirus Professional | 2017-09-18 | 6.9 MEDIUM | N/A |
aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625. | |||||
CVE-2009-3545 | 1 Datawizard | 1 Ftpxq Server | 2017-09-18 | 4.0 MEDIUM | N/A |
DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command. | |||||
CVE-2009-3549 | 2 Sun, Wireshark | 2 Sparc, Wireshark | 2017-09-18 | 5.0 MEDIUM | N/A |
packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. | |||||
CVE-2009-3753 | 1 Opial | 1 Opial | 2017-09-18 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php. | |||||
CVE-2009-4106 | 1 Ohloh | 1 Agoko Cms | 2017-09-18 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename and text parameters. | |||||
CVE-2009-4546 | 1 Logoshows | 1 Logoshows Bbs | 2017-09-18 | 7.5 HIGH | N/A |
globepersonnel_login.asp in Logoshows BBS 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) pb_username (aka pb%5Fusername) and (2) level cookies. | |||||
CVE-2015-6567 | 1 Wolfcms | 1 Wolf Cms | 2017-09-16 | 6.5 MEDIUM | 8.8 HIGH |
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality. | |||||
CVE-2015-6568 | 1 Wolfcms | 1 Wolf Cms | 2017-09-16 | 6.5 MEDIUM | 8.8 HIGH |
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality. | |||||
CVE-2017-6316 | 1 Citrix | 1 Netscaler Sd-wan | 2017-09-15 | 10.0 HIGH | 9.8 CRITICAL |
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID. | |||||
CVE-2017-1519 | 3 Ibm, Linux, Microsoft | 4 Db2, Db2 Connect, Linux Kernel and 1 more | 2017-09-15 | 4.3 MEDIUM | 5.9 MEDIUM |
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829. | |||||
CVE-2015-7830 | 2 Oracle, Wireshark | 2 Solaris, Wireshark | 2017-09-14 | 4.3 MEDIUM | N/A |
The pcapng_read_if_descr_block function in wiretap/pcapng.c in the pcapng parser in Wireshark 1.12.x before 1.12.8 uses too many levels of pointer indirection, which allows remote attackers to cause a denial of service (incorrect free and application crash) via a crafted packet that triggers interface-filter copying. | |||||
CVE-2017-14098 | 1 Digium | 1 Asterisk | 2017-09-14 | 5.0 MEDIUM | 7.5 HIGH |
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash. | |||||
CVE-2015-6782 | 1 Google | 1 Chrome | 2017-09-13 | 4.3 MEDIUM | N/A |
The Document::open function in WebKit/Source/core/dom/Document.cpp in Google Chrome before 47.0.2526.73 does not ensure that page-dismissal event handling is compatible with modal-dialog blocking, which makes it easier for remote attackers to spoof Omnibox content via a crafted web site. | |||||
CVE-2015-6385 | 1 Cisco | 1 Ios | 2017-09-13 | 7.2 HIGH | N/A |
The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943. | |||||
CVE-2015-6783 | 1 Google | 2 Android, Chrome | 2017-09-13 | 4.3 MEDIUM | N/A |
The FindStartOffsetOfFileInZipFile function in crazy_linker_zip.cpp in crazy_linker (aka Crazy Linker) in Android 5.x and 6.x, as used in Google Chrome before 47.0.2526.73, improperly searches for an EOCD record, which allows attackers to bypass a signature-validation requirement via a crafted ZIP archive. | |||||
CVE-2015-6784 | 1 Google | 1 Chrome | 2017-09-13 | 4.3 MEDIUM | N/A |
The page serializer in Google Chrome before 47.0.2526.73 mishandles Mark of the Web (MOTW) comments for URLs containing a "--" sequence, which might allow remote attackers to inject HTML via a crafted URL, as demonstrated by an initial http://example.com?-- substring. | |||||
CVE-2017-14105 | 1 Aerohive | 1 Hivemanager Classic | 2017-09-13 | 7.2 HIGH | 7.8 HIGH |
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker - even restricted as a tenant - can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface). | |||||
CVE-2015-5186 | 1 Linux Audit Project | 1 Linux Audit | 2017-09-13 | 5.0 MEDIUM | 5.3 MEDIUM |
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames. | |||||
CVE-2015-7094 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-09-12 | 2.6 LOW | N/A |
CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL. | |||||
CVE-2017-12939 | 2 Microsoft, Unity3d | 2 Windows, Unity Editor | 2017-09-12 | 7.5 HIGH | 9.8 CRITICAL |
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4. |