Unknown · CVSS Not scored
drivers/mmc/card/mmc_block_test.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not reject kernel-space buffer addresses, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769208 and Qualcomm internal bug CR547479.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted application, related to arch/arm/mach-msm/qdsp6v2/audio_utils.c and sound/soc/msm/qdsp6v2/q6asm.c, aka Android internal bug 28751152 and Qualcomm internal bug CR563086.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/media/platform/msm/camera_v2/isp/msm_isp_axi_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate the number of streams, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28749629 and Qualcomm internal bug CR514702.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/video/msm/vidc/common/enc/venc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate VEN_IOCTL_GET_SEQUENCE_HDR ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28769352 and Qualcomm internal bug CR556356.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices mishandles a user-space pointer, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28768281 and Qualcomm internal bug CR547231.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space input, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28748271 and Qualcomm internal bug CR550013.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer underflow in drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 28750726 and Qualcomm internal bug CR556860.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate a certain parameter, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747684 and Qualcomm internal bug CR511358.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges or obtain sensitive information via a crafted application, aka Android internal bug 28768146 and Qualcomm internal bug CR549470.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/char/diag/diag_dci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application that sends short DCI request packets, aka Android internal bug 28767589 and Qualcomm internal bug CR483310.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in drivers/media/platform/msm/camera_v2/isp/msm_isp_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allow attackers to gain privileges via a crafted application, aka Android internal bug 28749803 and Qualcomm internal bug CR514717.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
Published Aug 31, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not ensure unique identifiers in a DCI client table, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28750155 and Qualcomm internal bug CR590721.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28747998 and Qualcomm internal bug CR561841.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
drivers/media/platform/msm/camera_v2/sensor/csiphy/msm_csiphy.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via an application that provides a crafted mask value, aka Android internal bug 28749721 and Qualcomm internal bug CR511976.
Published Aug 6, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and attack vectors.
Published Aug 4, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure size consistency, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.
Published Aug 31, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter to permalink_page.php.
Published Aug 9, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.
Published Aug 31, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."
Published Aug 28, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
Published Aug 25, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and resulting web cache poisoning or cross-site scripting (XSS) attacks, or obtain sensitive information via multiple unspecified parameters.
Published Aug 25, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in BMC Footprints Service Core 11.5.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in vBulletin 3.5.4, 3.6.0, 3.6.7, 3.8.7, 4.2.2, 5.0.5, and 5.1.3.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple SQL injection vulnerabilities in SmartCMS v.2.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in mpg123 before 1.18.0.
Published Aug 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Emacs 24.4 allows remote attackers to bypass security restrictions.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate a certain id value, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.
Published Aug 7, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and consequently gain SYSTEM privileges via vectors involving CORBA calls, aka SAP Note 2039905.
Published Aug 9, 2021 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
Published Aug 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the "set configuration" box in the Configuration Report page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.17 allows remote administrators to inject arbitrary web script or HTML via the config_option parameter, a different vulnerability than CVE-2014-8986.
Published Aug 24, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in IBM UrbanCode Release 6.0.1.6 and earlier, 6.1.0.7 and earlier, and 6.1.1.1 and earlier.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.
Published Aug 2, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Cit-e-Net Cit-e-Access 6.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.
Published Aug 31, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.
Published Aug 31, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.
Published Aug 24, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.
Published Aug 31, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hard coded weak credentials in Barracuda Load Balancer 5.0.0.015.
Published Aug 28, 2017 · Updated Aug 6, 2024