Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-6769 | 1 Cisco | 1 Secure Access Control System | 2017-08-10 | 3.5 LOW | 5.4 MEDIUM |
A vulnerability in the web-based management interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCve70587. Known Affected Releases: 5.8(0.8) 5.8(1.5). | |||||
CVE-2015-4463 | 1 Efrontlearning | 1 Efront | 2017-08-10 | 4.0 MEDIUM | 6.5 MEDIUM |
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL. | |||||
CVE-2015-2798 | 1 Web-dorado | 1 Contact Form Maker | 2017-08-10 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2015-4462 | 1 Efrontlearning | 1 Efront | 2017-08-10 | 4.0 MEDIUM | 6.5 MEDIUM |
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php. | |||||
CVE-2015-6585 | 1 Hancom | 1 Hangul Word Processor | 2017-08-10 | 6.8 MEDIUM | 7.8 HIGH |
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag. | |||||
CVE-2015-8013 | 1 Openpgpjs | 1 Openpgpjs | 2017-08-10 | 5.0 MEDIUM | 7.5 HIGH |
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message. | |||||
CVE-2017-6612 | 1 Cisco | 1 Asr 5000 Series Software | 2017-08-10 | 5.0 MEDIUM | 8.6 HIGH |
A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927. | |||||
CVE-2017-11673 | 1 Acunetix | 1 Web Vulnerability Scanner | 2017-08-09 | 7.5 HIGH | 9.8 CRITICAL |
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE file, related to a "User Mode Write AV starting at reporter!madTraceProcess." | |||||
CVE-2017-11674 | 1 Acunetix | 1 Web Vulnerability Scanner | 2017-08-09 | 4.3 MEDIUM | 5.5 MEDIUM |
Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess." | |||||
CVE-2015-3839 | 1 Google | 1 Android | 2017-08-09 | 2.1 LOW | 5.5 MEDIUM |
The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash). | |||||
CVE-2017-11629 | 1 Finecms | 1 Finecms | 2017-08-09 | 4.3 MEDIUM | 6.1 MEDIUM |
dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=api&m=data2 request. | |||||
CVE-2017-11718 | 1 Metinfo Project | 1 Metinfo | 2017-08-09 | 5.8 MEDIUM | 6.1 MEDIUM |
There is URL Redirector Abuse in MetInfo through 5.3.17 via the gourl parameter to member/login.php. | |||||
CVE-2017-11716 | 1 Metinfo Project | 1 Metinfo | 2017-08-09 | 4.3 MEDIUM | 6.1 MEDIUM |
MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode. | |||||
CVE-2017-12419 | 3 Mantisbt, Mariadb, Mysql | 3 Mantisbt, Mariadb, Mysql | 2017-08-09 | 4.0 MEDIUM | 4.9 MEDIUM |
If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator does not remove the 'admin' directory (as recommended in the "Post-installation and upgrade tasks" section of the MantisBT Admin Guide), and the MySQL client has a local_infile setting enabled (in php.ini mysqli.allow_local_infile, or the MySQL client config file, depending on the PHP setup), an attacker may take advantage of MySQL's "connect file read" feature to remotely access files on the MantisBT server. | |||||
CVE-2017-11715 | 1 Metinfo Project | 1 Metinfo | 2017-08-09 | 6.5 MEDIUM | 9.8 CRITICAL |
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php. | |||||
CVE-2017-11760 | 1 Projeqtor | 1 Projeqtor | 2017-08-09 | 6.5 MEDIUM | 8.8 HIGH |
uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area. | |||||
CVE-2017-11742 | 2 Libexpat Project, Microsoft | 2 Libexpat, Windows | 2017-08-09 | 4.6 MEDIUM | 7.8 HIGH |
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking. | |||||
CVE-2017-11748 | 1 Softonic | 1 Spider Player | 2017-08-09 | 6.8 MEDIUM | 7.8 HIGH |
VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file. | |||||
CVE-2015-3642 | 1 Citrix | 3 Netscaler Application Delivery Controller, Netscaler Firmware, Netscaler Gateway | 2017-08-09 | 4.3 MEDIUM | 5.9 MEDIUM |
The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE). | |||||
CVE-2017-12414 | 1 Pcfreetime | 1 Format Factory | 2017-08-09 | 7.5 HIGH | 9.8 CRITICAL |
Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll. |