Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-6629 | 3 Artifex, Google, Oracle | 3 Gpl Ghostscript, Chrome, Solaris | 2018-01-04 | 5.0 MEDIUM | N/A |
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image. | |||||
CVE-2014-3698 | 1 Pidgin | 1 Pidgin | 2018-01-04 | 5.0 MEDIUM | N/A |
The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sensitive information from process memory via a crafted XMPP message. | |||||
CVE-2014-9419 | 1 Linux | 1 Linux Kernel | 2018-01-04 | 2.1 LOW | N/A |
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application that reads a TLS base address. | |||||
CVE-2017-8865 | 1 Cognitoys | 2 Stemosaur, Stemosaur Firmware | 2018-01-04 | 4.3 MEDIUM | 5.9 MEDIUM |
Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 do not provide sufficient protections against capture-replay attacks, allowing an attacker on the network to replay VoIP traffic between a Dino device and remote server to any other Dino device. | |||||
CVE-2017-17735 | 1 Cmsmadesimple | 1 Cms Made Simple | 2018-01-04 | 5.0 MEDIUM | 9.8 CRITICAL |
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies. | |||||
CVE-2017-17734 | 1 Cmsmadesimple | 1 Cms Made Simple | 2018-01-04 | 5.0 MEDIUM | 9.8 CRITICAL |
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions. | |||||
CVE-2017-1257 | 1 Ibm | 1 Security Guardium | 2018-01-03 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Security Guardium 10.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 124684. | |||||
CVE-2017-1261 | 1 Ibm | 1 Security Guardium | 2018-01-03 | 2.1 LOW | 3.3 LOW |
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736. | |||||
CVE-2017-17776 | 1 Paid To Read Script Project | 1 Paid To Read Script | 2018-01-03 | 5.0 MEDIUM | 5.3 MEDIUM |
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter. | |||||
CVE-2017-1595 | 1 Ibm | 1 Security Guardium | 2018-01-03 | 2.1 LOW | 5.5 MEDIUM |
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132549. | |||||
CVE-2017-1596 | 1 Ibm | 1 Security Guardium | 2018-01-03 | 2.1 LOW | 5.5 MEDIUM |
IBM Security Guardium 10.0 Database Activity Monitor could allow a local attacker to obtain highly sensitive information via unspecified vectors. IBM X-Force ID: 132550. | |||||
CVE-2017-16687 | 1 Sap | 1 Hana Database | 2018-01-02 | 5.0 MEDIUM | 5.3 MEDIUM |
The user self-service tools of SAP HANA extended application services, classic user self-service, a part of SAP HANA Database versions 1.00 and 2.00, can be misused to enumerate valid and invalid user accounts. An unauthenticated user could use the error messages to determine if a given username is valid. | |||||
CVE-2017-5117 | 4 Debian, Google, Linux and 1 more | 4 Debian Linux, Chrome, Linux Kernel and 1 more | 2017-12-30 | 4.3 MEDIUM | 6.5 MEDIUM |
Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | |||||
CVE-2017-16787 | 1 Meinbergglobal | 2 Lantime, Lantime Firmware | 2017-12-29 | 4.0 MEDIUM | 6.5 MEDIUM |
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access. | |||||
CVE-2012-1243 | 2 Google, Studiohitori | 2 Android, Twitrocker2 Android | 2017-12-28 | 5.0 MEDIUM | N/A |
The TwitRocker2 application before 1.0.23 for Android does not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |||||
CVE-2012-1945 | 1 Mozilla | 5 Firefox, Firefox Esr, Seamonkey and 2 more | 2017-12-28 | 2.9 LOW | N/A |
Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allow local users to obtain sensitive information via an HTML document that loads a shortcut (aka .lnk) file for display within an IFRAME element, as demonstrated by a network share implemented by (1) Microsoft Windows or (2) Samba. | |||||
CVE-2012-1960 | 1 Mozilla | 3 Firefox, Seamonkey, Thunderbird | 2017-12-28 | 5.0 MEDIUM | N/A |
The qcms_transform_data_rgb_out_lut_sse2 function in the QCMS implementation in Mozilla Firefox 4.x through 13.0, Thunderbird 5.0 through 13.0, and SeaMonkey before 2.11 might allow remote attackers to obtain sensitive information from process memory via a crafted color profile that triggers an out-of-bounds read operation. | |||||
CVE-2009-5112 | 1 Iwork | 1 Webglimpse | 2017-12-28 | 5.0 MEDIUM | N/A |
wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request. | |||||
CVE-2011-3670 | 1 Mozilla | 3 Firefox, Seamonkey, Thunderbird | 2017-12-28 | 5.0 MEDIUM | N/A |
Mozilla Firefox before 3.6.26 and 4.x through 6.0, Thunderbird before 3.1.18 and 5.0 through 6.0, and SeaMonkey before 2.4 do not properly enforce the IPv6 literal address syntax, which allows remote attackers to obtain sensitive information by making XMLHttpRequest calls through a proxy and reading the error messages. | |||||
CVE-2014-3801 | 1 Openstack | 1 Heat | 2017-12-28 | 3.5 LOW | N/A |
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list. |