Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0297 | 1 Keil Software | 1 Photokorn | 2017-09-28 | 5.0 MEDIUM | N/A |
PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output. | |||||
CVE-2008-0598 | 1 Linux | 1 Linux Kernel | 2017-09-28 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in the 32-bit and 64-bit emulation in the Linux kernel 2.6.9, 2.6.18, and probably other versions allows local users to read uninitialized memory via unknown vectors involving a crafted binary. | |||||
CVE-2008-0938 | 1 Sun | 1 Solaris | 2017-09-28 | 4.7 MEDIUM | N/A |
Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126. | |||||
CVE-2007-5654 | 1 Litespeed Technologies | 1 Litespeed Web Server | 2017-09-28 | 5.0 MEDIUM | N/A |
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00." sequence followed by a new extension, as demonstrated by reading PHP source code via requests for .php%00.txt files, aka "Mime Type Injection." | |||||
CVE-2007-5774 | 1 Flatnuke3 | 1 Flatnuke3 | 2017-09-28 | 5.0 MEDIUM | N/A |
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals the path in an error message. | |||||
CVE-2007-6476 | 1 Gf 3xplorer | 1 Gf 3xplorer | 2017-09-28 | 5.0 MEDIUM | N/A |
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php, which calls the phpinfo function. | |||||
CVE-2017-1346 | 1 Ibm | 1 Business Process Manager | 2017-09-28 | 1.9 LOW | 2.5 LOW |
IBM Business Process Manager 7.5, 8.0, and 8.5 temporarily stores files in a temporary folder during offline installs which could be read by a local user within a short timespan. IBM X-Force ID: 126461. | |||||
CVE-2017-8770 | 1 Twsz | 2 Wifi Repeater, Wifi Repeater Firmware | 2017-09-28 | 7.8 HIGH | 7.5 HIGH |
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter. | |||||
CVE-2017-12157 | 1 Moodle | 1 Moodle | 2017-09-28 | 4.0 MEDIUM | 4.3 MEDIUM |
In Moodle 3.x, various course reports allow teachers to view details about users in the groups they can't access. | |||||
CVE-2014-8174 | 1 Redhat | 1 Edeploy | 2017-09-28 | 7.5 HIGH | 9.8 CRITICAL |
eDeploy makes it easier for remote attackers to execute arbitrary code by leveraging use of HTTP to download files. | |||||
CVE-2017-0022 | 1 Microsoft | 8 Windows 10, Windows 7, Windows 8.1 and 5 more | 2017-09-27 | 4.3 MEDIUM | 4.3 MEDIUM |
Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site, aka "Microsoft XML Information Disclosure Vulnerability." | |||||
CVE-2017-9960 | 1 Schneider-electric | 1 U.motion Builder | 2017-09-27 | 5.0 MEDIUM | 5.3 MEDIUM |
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user. | |||||
CVE-2014-9616 | 1 Netsweeper | 1 Netsweeper | 2017-09-27 | 5.0 MEDIUM | 7.5 HIGH |
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page. | |||||
CVE-2017-13761 | 1 Fastly | 1 Fastly | 2017-09-26 | 4.0 MEDIUM | 6.5 MEDIUM |
The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses. | |||||
CVE-2017-11040 | 1 Google | 1 Android | 2017-09-26 | 4.3 MEDIUM | 5.5 MEDIUM |
In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to. | |||||
CVE-2017-11001 | 1 Google | 1 Android | 2017-09-26 | 4.3 MEDIUM | 5.5 MEDIUM |
In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read. | |||||
CVE-2017-10996 | 1 Google | 1 Android | 2017-09-26 | 7.1 HIGH | 5.5 MEDIUM |
In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access. | |||||
CVE-2017-9676 | 1 Google | 1 Android | 2017-09-26 | 2.6 LOW | 4.7 MEDIUM |
In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock. | |||||
CVE-2015-7880 | 1 Drupal | 1 Drupal | 2017-09-26 | 4.0 MEDIUM | 4.3 MEDIUM |
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames. | |||||
CVE-2017-1490 | 1 Ibm | 1 Jazz Reporting Service | 2017-09-23 | 3.5 LOW | 5.3 MEDIUM |
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information. |