Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by CWE-358
Total 28 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15706 1 Apache 1 Tomcat 2019-04-15 5.0 MEDIUM 5.3 MEDIUM
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expected and other scripts may have been executed unexpectedly. Note that the behaviour of the CGI servlet has remained unchanged in this regard. It is only the documentation of the behaviour that was wrong and has been corrected.
CVE-2017-7177 1 Openinfosecfoundation 1 Suricata 2018-12-05 5.0 MEDIUM 7.5 HIGH
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the IP protocol during fragment matching.
CVE-2017-15664 1 Flexense 1 Syncbreeze 2018-02-01 5.0 MEDIUM 7.5 HIGH
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121.
CVE-2017-15663 1 Flexense 1 Disk Pulse 2018-02-01 5.0 MEDIUM 7.5 HIGH
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
CVE-2017-15662 1 Flexense 1 Vx Search 2018-02-01 5.0 MEDIUM 7.5 HIGH
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
CVE-2017-15665 1 Flexense 1 Diskboss 2018-02-01 5.0 MEDIUM 7.5 HIGH
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
CVE-2017-8152 1 Huawei 2 Honor 5s, Honor 5s Firmware 2017-12-11 4.9 MEDIUM 4.6 MEDIUM
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory Reset Protection (FRP) bypass security vulnerability due to the improper design. An attacker can access factory reset page without authorization by only dial with special code. The attacker can exploit this vulnerability to restore the phone to factory settings.
CVE-2014-4843 1 Ibm 1 Curam Social Program Management 2017-06-15 5.0 MEDIUM 5.3 MEDIUM
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.5 iFix5 allows remote attackers to obtain sensitive information about internal caseworker usernames via vectors related to a URL.