| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-2894 | Cri | 0.64 | 9.8 | 0.05 | Nov 7, 2017 | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially… | ||
| CVE-2017-2892 | Cri | 0.64 | 9.8 | 0.02 | Nov 7, 2017 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of… | ||
| CVE-2017-2891 | Cri | 0.64 | 9.8 | 0.03 | Nov 7, 2017 | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send… | ||
| CVE-2017-2864 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2017 | An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker resulting in authentication bypass. An attacker can send a… | ||
| CVE-2017-12085 | Cri | 0.59 | 9.0 | 0.01 | Nov 7, 2017 | An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network connectivity to the Internet to trigger this vulnerability. | ||
| CVE-2017-15887 | Cri | 0.64 | 9.8 | 0.00 | Nov 7, 2017 | An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack. | ||
| CVE-2017-16638 | Cri | 0.64 | 9.8 | 0.00 | Nov 6, 2017 | The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script. | ||
| CVE-2017-16548 | Cri | 0.64 | 9.8 | 0.03 | Nov 6, 2017 | The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified… | ||
| CVE-2017-16543 | Cri | 0.67 | 9.8 | 0.02 | Nov 5, 2017 | Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter. | ||
| CVE-2017-1000171 | Cri | 0.64 | 9.8 | 0.00 | Nov 3, 2017 | Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text. | ||
| CVE-2017-1000154 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2017 | Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended. | ||
| CVE-2017-1000153 | Cri | 0.64 | 9.8 | 0.00 | Nov 3, 2017 | Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can… | ||
| CVE-2017-1000152 | Cri | 0.64 | 9.8 | 0.00 | Nov 3, 2017 | Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out… | ||
| CVE-2017-16523 | Cri | 0.64 | 9.8 | 0.03 | Nov 3, 2017 | MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented. | ||
| CVE-2017-11767 | — | Cri | 0.58 | 9.8 | 0.17 | Nov 2, 2017 | ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". | |
| CVE-2017-16510 | Cri | 0.57 | 9.8 | 0.04 | Nov 2, 2017 | WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723. | ||
| CVE-2017-1000121 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2017 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect… | ||
| CVE-2017-1000245 | Cri | 0.64 | 9.8 | 0.00 | Nov 1, 2017 | The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file. | ||
| CVE-2017-14027 | Cri | 0.64 | 9.8 | 0.00 | Nov 1, 2017 | A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC… | ||
| CVE-2017-14021 | Cri | 0.64 | 9.8 | 0.00 | Nov 1, 2017 | A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d,… | ||
| CVE-2017-15535 | Cri | 0.59 | 9.1 | 0.00 | Nov 1, 2017 | MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify… | ||
| CVE-2017-14375 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2017 | EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including… | ||
| CVE-2017-1000257 | Cri | 0.59 | 9.1 | 0.01 | Oct 31, 2017 | An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data… | ||
| CVE-2017-14356 | Cri | 0.64 | 9.8 | 0.01 | Oct 31, 2017 | An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection. | ||
| CVE-2017-15993 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | ||
| CVE-2017-15992 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php. | ||
| CVE-2017-15991 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951,… | ||
| CVE-2017-15990 | Cri | 0.67 | 9.8 | 0.09 | Oct 31, 2017 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. | ||
| CVE-2017-15989 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action. | ||
| CVE-2017-15988 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525. | ||
| CVE-2017-15987 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter. | ||
| CVE-2017-15986 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | CPA Lead Reward Script allows SQL Injection via the username parameter. | ||
| CVE-2017-15985 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter. | ||
| CVE-2017-15984 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php. | ||
| CVE-2017-15983 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | ||
| CVE-2017-15982 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | ||
| CVE-2017-15981 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing. | ||
| CVE-2017-15980 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter. | ||
| CVE-2017-15979 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter. | ||
| CVE-2017-15978 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter. | ||
| CVE-2017-15977 | Cri | 0.67 | 9.8 | 0.01 | Oct 31, 2017 | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | ||
| CVE-2015-9245 | Cri | 0.64 | 9.8 | 0.00 | Oct 31, 2017 | Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931. | ||
| CVE-2017-10151 | Cri | 0.66 | 10.0 | 0.14 | Oct 30, 2017 | Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | ||
| CVE-2014-0073 | Cri | 0.58 | 9.8 | 0.11 | Oct 30, 2017 | The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote… | ||
| CVE-2013-4366 | Cri | 0.57 | 9.8 | 0.01 | Oct 30, 2017 | http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification. | ||
| CVE-2012-4449 | Cri | 0.64 | 9.8 | 0.00 | Oct 30, 2017 | Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack. | ||
| CVE-2017-15597 | Cri | 0.59 | 9.1 | 0.01 | Oct 30, 2017 | An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a… | ||
| CVE-2015-3249 | Cri | 0.64 | 9.8 | 0.04 | Oct 30, 2017 | The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2)… | ||
| CVE-2014-3624 | Cri | 0.64 | 9.8 | 0.00 | Oct 30, 2017 | Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT. | ||
| CVE-2012-5358 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2017 | The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrary files and consequently bypass authentication, modify viewstate, cause a denial… |
- risk 0.64cvss 9.8epss 0.05
An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause a stack buffer overflow resulting in remote code execution. An attacker needs to send a specially…
- risk 0.64cvss 9.8epss 0.02
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of…
- risk 0.64cvss 9.8epss 0.03
An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinary HTTP POST request with a CGI target can cause a reuse of previously freed pointer potentially resulting in remote code execution. An attacker needs to send…
- risk 0.64cvss 9.8epss 0.01
An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Specially crafted network packets can cause a valid authentication token to be returned to the attacker resulting in authentication bypass. An attacker can send a…
- risk 0.59cvss 9.0epss 0.01
An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet can make the Circle cloud route a packet to any arbitrary Circle device. An attacker needs network connectivity to the Internet to trigger this vulnerability.
- risk 0.64cvss 9.8epss 0.00
An improper restriction of excessive authentication attempts vulnerability in /principals in Synology CardDAV Server before 6.0.7-0085 allows remote attackers to obtain user credentials via a brute-force attack.
- risk 0.64cvss 9.8epss 0.00
The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.
- risk 0.64cvss 9.8epss 0.03
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified…
- risk 0.67cvss 9.8epss 0.02
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.
- risk 0.64cvss 9.8epss 0.00
Mahara Mobile before 1.2.1 is vulnerable to passwords being sent to the Mahara access log in plain text.
- risk 0.64cvss 9.8epss 0.01
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to some authentication methods, which do not use Mahara's built-in login form, still allowing users to log in even if their institution was expired or suspended.
- risk 0.64cvss 9.8epss 0.00
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently the link in email can…
- risk 0.64cvss 9.8epss 0.00
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out…
- risk 0.64cvss 9.8epss 0.03
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented.
- risk 0.58cvss 9.8epss 0.17
ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".
- risk 0.57cvss 9.8epss 0.04
WordPress before 4.8.3 is affected by an issue where $wpdb->prepare() can create unexpected and unsafe queries leading to potential SQL injection (SQLi) in plugins and themes, as demonstrated by a "double prepare" approach, a different vulnerability than CVE-2017-14723.
- risk 0.64cvss 9.8epss 0.01
The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondary process to trigger an integer overflow and subsequent buffer overflow in the UI process. This vulnerability does not affect…
- risk 0.64cvss 9.8epss 0.00
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.
- risk 0.64cvss 9.8epss 0.00
A Use of Hard-coded Credentials issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d, JetNet6710G-HVDC…
- risk 0.64cvss 9.8epss 0.00
A Use of Hard-coded Cryptographic Key issue was discovered in Korenix JetNet JetNet5018G version 1.4, JetNet5310G version 1.4a, JetNet5428G-2G-2FX version 1.4, JetNet5628G-R version 1.4, JetNet5628G version 1.4, JetNet5728G-24P version 1.4, JetNet5828G version 1.1d,…
- risk 0.59cvss 9.1epss 0.00
MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enabled that could be exploited by a malicious attacker to deny service or modify…
- risk 0.64cvss 9.8epss 0.02
EMC Unisphere for VMAX Virtual Appliance (vApp) versions prior to 8.4.0.15, EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.15, EMC VASA Virtual Appliance versions prior to 8.4.0.512, and EMC VMAX Embedded Management (eManagement) versions prior to and including…
- risk 0.59cvss 9.1epss 0.01
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data…
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow SQL injection.
- risk 0.67cvss 9.8epss 0.01
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
- risk 0.67cvss 9.8epss 0.01
Website Broker Script allows SQL Injection via the 'status_id' Parameter to status_list.php.
- risk 0.67cvss 9.8epss 0.01
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951,…
- risk 0.67cvss 9.8epss 0.09
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
- risk 0.67cvss 9.8epss 0.01
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
- risk 0.67cvss 9.8epss 0.01
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.
- risk 0.67cvss 9.8epss 0.01
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
- risk 0.67cvss 9.8epss 0.01
CPA Lead Reward Script allows SQL Injection via the username parameter.
- risk 0.67cvss 9.8epss 0.01
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
- risk 0.67cvss 9.8epss 0.01
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
- risk 0.67cvss 9.8epss 0.01
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- risk 0.67cvss 9.8epss 0.01
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- risk 0.67cvss 9.8epss 0.01
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing.
- risk 0.67cvss 9.8epss 0.01
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
- risk 0.67cvss 9.8epss 0.01
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
- risk 0.67cvss 9.8epss 0.01
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
- risk 0.67cvss 9.8epss 0.01
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
- risk 0.64cvss 9.8epss 0.00
Insecure default configuration in Progress Software OpenEdge 10.2x and 11.x allows unauthenticated remote attackers to specify arbitrary URLs from which to load and execute malicious Java classes via port 20931.
- risk 0.66cvss 10.0epss 0.14
Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Default Account). Supported versions that are affected are 11.1.1.7, 11.1.2.3 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
- risk 0.58cvss 9.8epss 0.11
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote…
- risk 0.57cvss 9.8epss 0.01
http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows attackers to have unspecified impact via vectors involving hostname verification.
- risk 0.64cvss 9.8epss 0.00
Apache Hadoop before 0.23.4, 1.x before 1.0.4, and 2.x before 2.0.2 generate token passwords using a 20-bit secret when Kerberos security features are enabled, which makes it easier for context-dependent attackers to crack secret keys via a brute-force attack.
- risk 0.59cvss 9.1epss 0.01
An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a…
- risk 0.64cvss 9.8epss 0.04
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2)…
- risk 0.64cvss 9.8epss 0.00
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
- risk 0.64cvss 9.8epss 0.01
The XSLTCompiledTransform function in Ektron Content Management System (CMS) before 8.02 SP5 configures the XSL with enableDocumentFunction set to true, which allows remote attackers to read arbitrary files and consequently bypass authentication, modify viewstate, cause a denial…