Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-1178 | 1 Appleple | 1 A-blog Cms | 2017-04-20 | 6.4 MEDIUM | 6.5 MEDIUM |
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors. | |||||
CVE-2017-7719 | 1 Web-dorado | 1 Spider Event Calendar | 2017-04-20 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php. | |||||
CVE-2016-8727 | 1 Moxa | 2 Awk-3131a, Awk-3131a Firmware | 2017-04-20 | 5.0 MEDIUM | 7.5 HIGH |
An exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point. Retrieving a series of URLs without authentication can reveal sensitive configuration and system information to an attacker. | |||||
CVE-2015-7564 | 1 Teampass | 1 Teampass | 2017-04-20 | 7.5 HIGH | 9.8 CRITICAL |
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php. | |||||
CVE-2016-1179 | 1 Appleple | 1 A-blog Cms | 2017-04-20 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML. | |||||
CVE-2016-1886 | 1 Freebsd | 1 Freebsd | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow." | |||||
CVE-2017-7874 | 2017-04-19 | N/A | N/A | ||
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | |||||
CVE-2016-4898 | 1 Novastor | 1 Novabackup Datacenter | 2017-04-19 | 10.0 HIGH | 9.8 CRITICAL |
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors. | |||||
CVE-2016-4899 | 1 Novastor | 1 Novabackup Datacenter | 2017-04-19 | 10.0 HIGH | 9.8 CRITICAL |
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors. | |||||
CVE-2016-5856 | 2 Google, Linux | 2 Android, Linux Kernel | 2017-04-19 | 7.6 HIGH | 7.0 HIGH |
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857. | |||||
CVE-2016-4897 | 1 Webmin | 1 Usermin | 2017-04-19 | 4.3 MEDIUM | 6.1 MEDIUM |
Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. | |||||
CVE-2016-4337 | 1 Ktools | 1 Photostore | 2017-04-19 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action. | |||||
CVE-2016-10121 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. | |||||
CVE-2016-10122 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail does not properly clean environment variables, which allows local users to gain privileges. | |||||
CVE-2016-10120 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. | |||||
CVE-2016-10123 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. | |||||
CVE-2016-10118 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 2.1 LOW | 3.3 LOW |
Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. | |||||
CVE-2016-10119 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. | |||||
CVE-2016-10117 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. | |||||
CVE-2015-8282 | 1 Seawell Networks | 1 Spectrum Sdc | 2017-04-19 | 7.5 HIGH | 9.8 CRITICAL |
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account. |