Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-2620 | 1 Firebirdsql | 1 Firebird | 2017-09-19 | 5.0 MEDIUM | N/A |
src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference. | |||||
CVE-2009-2261 | 1 Giorgio Tani | 1 Peazip | 2017-09-19 | 9.3 HIGH | N/A |
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command. | |||||
CVE-2009-2655 | 1 Microsoft | 2 Internet Explorer, Windows Xp | 2017-09-19 | 4.3 MEDIUM | N/A |
mshtml.dll in Microsoft Internet Explorer 7 and 8 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) by calling the JavaScript findText method with a crafted Unicode string in the first argument, and only one additional argument, as demonstrated by a second argument of -1. | |||||
CVE-2015-6568 | 1 Wolfcms | 1 Wolf Cms | 2017-09-17 | 6.5 MEDIUM | 8.8 HIGH |
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality. | |||||
CVE-2015-6567 | 1 Wolfcms | 1 Wolf Cms | 2017-09-17 | 6.5 MEDIUM | 8.8 HIGH |
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality. | |||||
CVE-2017-1519 | 3 Ibm, Linux, Microsoft | 4 Db2, Db2 Connect, Linux Kernel and 1 more | 2017-09-15 | 4.3 MEDIUM | 5.9 MEDIUM |
IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829. | |||||
CVE-2017-14098 | 1 Digium | 1 Asterisk | 2017-09-14 | 5.0 MEDIUM | 7.5 HIGH |
In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash. | |||||
CVE-2015-6385 | 1 Cisco | 1 Ios | 2017-09-14 | 7.2 HIGH | N/A |
The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943. | |||||
CVE-2017-14105 | 1 Aerohive | 1 Hivemanager Classic | 2017-09-13 | 7.2 HIGH | 7.8 HIGH |
HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker - even restricted as a tenant - can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface). | |||||
CVE-2015-5186 | 1 Linux Audit Project | 1 Linux Audit | 2017-09-13 | 5.0 MEDIUM | 5.3 MEDIUM |
Audit before 2.4.4 in Linux does not sanitize escape characters in filenames. | |||||
CVE-2015-7094 | 1 Apple | 2 Iphone Os, Mac Os X | 2017-09-13 | 2.6 LOW | N/A |
CFNetwork HTTPProtocol in Apple iOS before 9.2 and OS X before 10.11.2 allows man-in-the-middle attackers to bypass the HSTS protection mechanism via a crafted URL. | |||||
CVE-2017-12939 | 2 Microsoft, Unity3d | 2 Windows, Unity Editor | 2017-09-13 | 7.5 HIGH | 9.8 CRITICAL |
A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x before 5.5.4p3, 5.6.x before 5.6.3p1, and 2017.x before 2017.1.0p4. | |||||
CVE-2017-9945 | 1 Siemens | 2 7km Pac Switched Ethernet Profinet Expansion Module, 7km Pac Switched Ethernet Profinet Expansion Module Firmware | 2017-09-12 | 6.1 MEDIUM | 6.5 MEDIUM |
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover. | |||||
CVE-2015-0234 | 1 Pki-core Project | 1 Pki-core | 2017-09-12 | 5.0 MEDIUM | 7.5 HIGH |
Multiple temporary file creation vulnerabilities in pki-core 10.2.0. | |||||
CVE-2016-1284 | 1 Isc | 1 Bind | 2017-09-10 | 2.6 LOW | 5.9 MEDIUM |
rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query. | |||||
CVE-2014-6097 | 1 Ibm | 1 Db2 | 2017-09-08 | 4.0 MEDIUM | N/A |
IBM DB2 9.7 before FP10 and 9.8 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement. | |||||
CVE-2014-6159 | 1 Ibm | 1 Db2 | 2017-09-08 | 3.5 LOW | N/A |
IBM DB2 9.7 before FP10, 9.8 through FP5, 10.1 through FT4, and 10.5 through FP4 on Linux, UNIX, and Windows, when immediate AUTO_REVAL is enabled, allows remote authenticated users to cause a denial of service (daemon crash) via a crafted ALTER TABLE statement. | |||||
CVE-2014-6151 | 1 Ibm | 1 Tivoli Integrated Portal | 2017-09-08 | 3.5 LOW | N/A |
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | |||||
CVE-2014-7990 | 1 Cisco | 4 Air-ct5760, Ios Xe, Ws-c3850 and 1 more | 2017-09-08 | 6.8 MEDIUM | N/A |
Cisco IOS XE 3.5E and earlier on WS-C3850, WS-C3860, and AIR-CT5760 devices does not properly parse the "request system shell" challenge response, which allows local users to obtain Linux root access by leveraging administrative privilege, aka Bug ID CSCur09815. | |||||
CVE-2012-6687 | 1 Fastcgi | 1 Fcgi | 2017-09-08 | 5.0 MEDIUM | N/A |
FastCGI (aka fcgi and libfcgi) 2.4.0 allows remote attackers to cause a denial of service (segmentation fault and crash) via a large number of connections. |