Skip directly to content

National Vulnerability Database - sponsored by NIST/DHS

Subscribe to National Vulnerability Database - sponsored by NIST/DHS feed
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Updated: 16 hours 14 min ago

CVE-2017-6002

Sun, 03/26/2017 - 22:59
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.

CVE-2017-6003

Sun, 03/26/2017 - 22:59
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.

CVE-2017-6006

Sun, 03/26/2017 - 22:59
Symphony 2.6.11 has XSS in publish/articles/new/ via the Body field.

CVE-2017-6013

Sun, 03/26/2017 - 22:59
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

CVE-2017-6066

Sun, 03/26/2017 - 22:59
Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.

CVE-2017-6067

Sun, 03/26/2017 - 22:59
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.

CVE-2017-6068

Sun, 03/26/2017 - 22:59
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

CVE-2017-6069

Sun, 03/26/2017 - 22:59
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

CVE-2017-7269

Sun, 03/26/2017 - 22:59
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If:

CVE-2017-5622

Sun, 03/26/2017 - 16:59
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

CVE-2017-2641

Sun, 03/26/2017 - 14:59
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

CVE-2017-2643

Sun, 03/26/2017 - 14:59
In Moodle 3.2.x, global search displays user names for unauthenticated users.

CVE-2017-2644

Sun, 03/26/2017 - 14:59
In Moodle 3.x, XSS can occur via evidence of prior learning.

CVE-2017-2645

Sun, 03/26/2017 - 14:59
In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

CVE-2016-10273

Sun, 03/26/2017 - 01:59
Multiple stack buffer overflow vulnerabilities in Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary code or crash the web service via the (1) ateFunc, (2) ateGain, (3) ateTxCount, (4) ateChan, (5) ateRate, (6) ateMacID, (7) e2pTxPower1, (8) e2pTxPower2, (9) e2pTxPower3, (10) e2pTxPower4, (11) e2pTxPower5, (12) e2pTxPower6, (13) e2pTxPower7, (14) e2pTx2Power1, (15) e2pTx2Power2, (16) e2pTx2Power3, (17) e2pTx2Power4, (18) e2pTx2Power5, (19) e2pTx2Power6, (20) e2pTx2Power7, (21) ateTxFreqOffset, (22) ateMode, (23) ateBW, (24) ateAntenna, (25) e2pTxFreqOffset, (26) e2pTxPwDeltaB, (27) e2pTxPwDeltaG, (28) e2pTxPwDeltaMix, (29) e2pTxPwDeltaN, and (30) readE2P parameters of the /goform/formWlanMP endpoint.

CVE-2017-7263

Sun, 03/26/2017 - 01:59
The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

CVE-2017-7264

Sun, 03/26/2017 - 01:59
Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

CVE-2017-7266

Sun, 03/26/2017 - 01:59
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

CVE-2017-7262

Fri, 03/24/2017 - 20:59
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.

CVE-2017-7261

Fri, 03/24/2017 - 17:59
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.

Pages