Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1693 1 Ibm 1 Integration Bus 2018-02-05 6.8 MEDIUM 5.6 MEDIUM
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to hijack another users session during a small timeframe before the session times out. IBM X-Force ID: 134164.
CVE-2018-1045 1 Moodle 1 Moodle 2018-02-05 3.5 LOW 5.4 MEDIUM
In Moodle 3.x, there is XSS via a calendar event name.
CVE-2018-1044 1 Moodle 1 Moodle 2018-02-05 4.0 MEDIUM 4.3 MEDIUM
In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.
CVE-2016-0215 5 Hp, Ibm, Linux and 2 more 6 Hp-ux, Aix, Db2 and 3 more 2018-02-05 4.0 MEDIUM 6.5 MEDIUM
IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of service (daemon crash) via a SELECT statement with a subquery containing the AVG OLAP function on an Oracle compatible database.
CVE-2016-0219 1 Ibm 8 Rational Collaborative Lifecycle Management, Rational Doors Next Generation, Rational Engineering Lifecycle Manager and 5 more 2018-02-05 4.0 MEDIUM 6.5 MEDIUM
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote authenticated users to cause a denial of service via crafted XML data. IBM X-Force ID: 109693.
CVE-2014-9485 1 Minizip Project 1 Minizip 2018-02-05 4.3 MEDIUM 5.5 MEDIUM
Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive.
CVE-2017-16863 1 Atlassian 1 Jira 2018-02-05 4.3 MEDIUM 6.1 MEDIUM
The PieChart gadget in Atlassian Jira before version 7.5.3 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a project or filter.
CVE-2017-18033 1 Atlassian 1 Jira 2018-02-05 4.3 MEDIUM 6.5 MEDIUM
The Jira-importers-plugin in Atlassian Jira before version 7.6.1 allows remote attackers to create new projects and abort an executing external system import via various Cross-site request forgery (CSRF) vulnerabilities.
CVE-2014-6027 1 Torrentflux Project 1 Torrentflux 2018-02-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading a torrent file or (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a link to torrent details.
CVE-2018-5479 1 Foxsash 1 Imghosting 2018-02-05 4.3 MEDIUM 6.1 MEDIUM
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.
CVE-2017-15266 1 Gnu 1 Libextractor 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
CVE-2017-1000472 2 Debian, Pocoproject 2 Debian Linux, Poco 2018-02-04 5.8 MEDIUM 6.5 MEDIUM
The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attackers to conduct absolute path traversal attacks during the ZIP decompression, and possibly create or overwrite arbitrary files, via a crafted ZIP file, related to a "file path injection vulnerability".
CVE-2017-15954 2 Bchunk Project, Debian 2 Bchunk, Debian Linux 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file.
CVE-2017-15953 2 Bchunk Project, Debian 2 Bchunk, Debian Linux 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.
CVE-2017-15922 1 Gnu 1 Libextractor 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
CVE-2017-15955 2 Bchunk Project, Debian 2 Bchunk, Debian Linux 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file.
CVE-2017-16898 1 Libming 1 Libming 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.
CVE-2017-16883 1 Libming 1 Libming 2018-02-04 4.3 MEDIUM 6.5 MEDIUM
The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.
CVE-2017-16663 1 Sam2p Project 1 Sam2p 2018-02-04 4.3 MEDIUM 5.5 MEDIUM
In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width * height" multiplications occur unsafely.
CVE-2016-10516 1 Palletsprojects 1 Werkzeug 2018-02-04 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote attackers to inject arbitrary web script or HTML via a field that contains an exception message.
CVE-2017-1000211 1 Lynx Project 1 Lynx 2018-02-04 5.0 MEDIUM 5.3 MEDIUM
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
CVE-2017-15717 1 Apache 2 Sling Xss Protection Api, Sling Xss Protection Api Compat 2018-02-02 4.3 MEDIUM 6.1 MEDIUM
A flaw in the way URLs are escaped and encoded in the org.apache.sling.xss.impl.XSSAPIImpl#getValidHref and org.apache.sling.xss.impl.XSSFilterImpl#isValidHref allows special crafted URLs to pass as valid, although they carry XSS payloads. The affected versions are Apache Sling XSS Protection API 1.0.4 to 1.0.18, Apache Sling XSS Protection API Compat 1.1.0 and Apache Sling XSS Protection API 2.0.0.
CVE-2018-5301 1 Magento 1 Magento 2018-02-02 5.8 MEDIUM 6.5 MEDIUM
Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.
CVE-2014-5509 1 Clipboard Project 1 Clipboard 2018-02-02 3.6 LOW 5.5 MEDIUM
clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.
CVE-2017-12097 1 Delayed Job Web Project 1 Delayed Job Web 2018-02-02 4.3 MEDIUM 6.1 MEDIUM
An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
CVE-2017-12098 1 Rails Admin Project 1 Rails Admin 2018-02-02 4.3 MEDIUM 6.1 MEDIUM
An exploitable cross site scripting (XSS) vulnerability exists in the add filter functionality of the rails_admin rails gem version 1.2.0. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
CVE-2018-5687 1 Newsbee Project 1 Newsbee 2018-02-02 3.5 LOW 4.8 MEDIUM
NewsBee allows XSS via the Company Name field in the Settings under admin/admin.php.
CVE-2018-5715 1 Sugarcrm 1 Sugarcrm 2018-02-02 4.3 MEDIUM 6.1 MEDIUM
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
CVE-2018-5258 1 Banconeon 1 Neon 2018-02-02 4.3 MEDIUM 5.9 MEDIUM
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2018-5071 1 Cobham 2 Sea Tel 116, Sea Tel 116 Firmware 2018-02-02 3.5 LOW 5.4 MEDIUM
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.
CVE-2017-9796 1 Apache 1 Geode 2018-02-02 3.5 LOW 5.3 MEDIUM
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
CVE-2017-5699 1 Intel 2 Minnowboard 3, Minnowboard 3 Firmware 2018-02-02 2.1 LOW 5.5 MEDIUM
Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs.
CVE-2017-16865 1 Atlassian 1 Jira 2018-02-02 3.5 LOW 5.3 MEDIUM
The Trello importer in Atlassian Jira before version 7.6.1 allows remote attackers to access the content of internal network resources via a Server Side Request Forgery (SSRF). When running in an environment like Amazon EC2, this flaw maybe used to access to a metadata resource that provides access credentials and other potentially confidential information.
CVE-2018-5728 1 Cobham 2 Seatel 121, Seatel 121 Firmware 2018-02-02 5.0 MEDIUM 5.3 MEDIUM
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus request, as demonstrated by the Latitude/Longitude of the ship, or satellite details.
CVE-2016-5063 1 Bmc 1 Server Automation 2018-02-02 5.0 MEDIUM 5.3 MEDIUM
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.
CVE-2018-0785 1 Microsoft 1 Asp.net Core 2018-02-01 4.3 MEDIUM 6.5 MEDIUM
ASP.NET Core 1.0. 1.1, and 2.0 allow a cross site request forgery vulnerability due to the ASP.NET Core project templates, aka "ASP.NET Core Cross Site Request Forgery Vulnerability".
CVE-2016-0207 1 Ibm 1 Algo Risk Application 2018-02-01 3.5 LOW 5.4 MEDIUM
IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecified vectors. IBM X-Force ID: 109399.
CVE-2015-7484 1 Ibm 1 Rational Engineering Lifecycle Manager 2018-02-01 4.0 MEDIUM 4.3 MEDIUM
IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1 and 4.0 before 4.0.7 iFix10 allow remote authenticated users with access to lifecycle projects to obtain sensitive information by sending a crafted URL to the Lifecycle Query Engine. IBM X-Force ID: 108619.
CVE-2015-2981 1 Yodobashi 1 Yodobashi 2018-02-01 4.3 MEDIUM 5.9 MEDIUM
The Yodobashi App for Android 1.2.1.0 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-16514 1 Websitebaker 1 Websitebaker 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /install/index.php (Site Title) in WebsiteBaker 2.10.0 allow attackers to insert persistent JavaScript code that gets reflected back to users in multiple areas in the application.
CVE-2017-1000465 1 Sulu 1 Sulu-standard 2018-02-01 3.5 LOW 5.4 MEDIUM
Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-18024 1 Avantfax 1 Avantfax 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
AvantFAX 3.3.3 has XSS via an arbitrary parameter name to the default URI, as demonstrated by a parameter whose name contains a SCRIPT element and whose value is 1.
CVE-2017-14594 1 Atlassian 1 Jira 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query parameter.
CVE-2017-7998 1 Gespage 1 Gespage 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username parameter to webapp/users/user_reg.jsp.
CVE-2015-7485 1 Ibm 1 Rational Engineering Lifecycle Manager 2018-02-01 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108626.
CVE-2017-18023 1 Officetracker 1 Officetracker 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.
CVE-2017-14096 1 Trendmicro 1 Smart Protection Server 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.
CVE-2015-7486 1 Ibm 1 Rational Engineering Lifecycle Manager 2018-02-01 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108633.
CVE-2015-7474 1 Ibm 1 Rational Engineering Lifecycle Manager 2018-02-01 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in Jazz Foundation in IBM Rational Engineering Lifecycle Manager 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.2 iFix15, and 6.0 before 6.0.1 iFix4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 108501.
CVE-2018-5776 1 Wordpress 1 Wordpress 2018-02-01 4.3 MEDIUM 6.1 MEDIUM
WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).