Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-2970 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader Dc and 3 more | 2017-01-26 | 9.3 HIGH | 7.8 HIGH |
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the XSLT engine related to template manipulation. Successful exploitation could lead to arbitrary code execution. | |||||
CVE-2017-5556 | 2 Foxitsoftware, Microsoft | 3 Foxit Reader, Phantompdf, Windows | 2017-01-26 | 5.8 MEDIUM | 8.1 HIGH |
The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. | |||||
CVE-2017-5575 | 1 Metalgenix | 1 Genixcms | 2017-01-26 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter. | |||||
CVE-2016-5091 | 1 Typo3 | 1 Typo3 | 2017-01-26 | 6.8 MEDIUM | 8.1 HIGH |
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action. | |||||
CVE-2015-4626 | 1 Treasuryxpress | 1 C2box | 2017-01-26 | 5.0 MEDIUM | 7.5 HIGH |
B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative value in an overdraft. | |||||
CVE-2016-9081 | 1 Joomla | 1 Joomla\! | 2017-01-26 | 7.5 HIGH | 9.8 CRITICAL |
Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors. | |||||
CVE-2016-9012 | 1 Arista | 1 Cloudvision Portal | 2017-01-26 | 6.5 MEDIUM | 8.8 HIGH |
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle. | |||||
CVE-2017-5553 | 1 B2evolution | 1 B2evolution | 2017-01-26 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL. | |||||
CVE-2016-2783 | 1 Avaya | 1 Vsp Operating System Software | 2017-01-26 | 10.0 HIGH | 9.8 CRITICAL |
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames. | |||||
CVE-2017-5574 | 1 Metalgenix | 1 Genixcms | 2017-01-26 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter. | |||||
CVE-2017-5569 | 1 Eclinicalworks | 1 Patient Portal | 2017-01-26 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | |||||
CVE-2017-5570 | 1 Eclinicalworks | 1 Patient Portal | 2017-01-26 | 6.5 MEDIUM | 8.8 HIGH |
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | |||||
CVE-2016-4484 | 1 Cryptsetup Project | 1 Cryptsetup | 2017-01-25 | 7.2 HIGH | 6.8 MEDIUM |
The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password. | |||||
CVE-2016-6517 | 1 Liferay | 1 Liferay | 2017-01-25 | 7.5 HIGH | 9.8 CRITICAL |
Directory traversal vulnerability in Liferay 5.1.0 allows remote attackers to have unspecified impact via a %2E%2E (encoded dot dot) in the minifierBundleDir parameter to barebone.jsp. | |||||
CVE-2016-6521 | 1 Gopivotal | 1 Grails | 2017-01-25 | 6.8 MEDIUM | 8.8 HIGH |
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code via unspecified vectors. | |||||
CVE-2016-7792 | 1 Ubiquiti Networks | 2 Unifi Ap Ac Lite, Unifi Ap Ac Lite Firmware | 2017-01-25 | 8.3 HIGH | 8.8 HIGH |
Ubiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the database by directly connecting to it. | |||||
CVE-2017-5475 | 1 S9y | 1 Serendipity | 2017-01-25 | 6.8 MEDIUM | 8.8 HIGH |
comment.php in Serendipity through 2.0.5 allows CSRF in deleting any comments. | |||||
CVE-2017-5476 | 1 S9y | 1 Serendipity | 2017-01-25 | 6.8 MEDIUM | 8.8 HIGH |
Serendipity through 2.0.5 allows CSRF for the installation of an event plugin or a sidebar plugin. | |||||
CVE-2017-5474 | 1 S9y | 1 Serendipity | 2017-01-25 | 5.8 MEDIUM | 6.1 MEDIUM |
Open redirect vulnerability in comment.php in Serendipity through 2.0.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the HTTP Referer header. | |||||
CVE-2017-2578 | 1 Moodle | 1 Moodle | 2017-01-25 | 4.3 MEDIUM | 6.1 MEDIUM |
In Moodle 3.x, there is XSS in the assignment submission page. |