Medium · CVSS 4.9
A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.
Published Jul 27, 2018 · Updated Aug 5, 2024
High · CVSS 7.7
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
Published Jul 27, 2018 · Updated Aug 5, 2024
High · CVSS 8.1
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.
Published Jul 27, 2018 · Updated Aug 5, 2024
High · CVSS 8.7
It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored locally and are not passed between the client and the end URL) which means all clients using that proxy are sharing the same cookies.
Published Jul 26, 2018 · Updated Aug 5, 2024
Medium · CVSS 5.5
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A privileged user inside a guest could use this flaw to crash the QEMU process resulting in DoS or potentially execute arbitrary code on the host with privileges of QEMU process on the host.
Published Jul 2, 2018 · Updated Aug 5, 2024
Low · CVSS 3.3
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
Published Jul 27, 2018 · Updated Aug 5, 2024
Medium · CVSS 6.5
It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.
Published Jul 26, 2018 · Updated Aug 5, 2024
Low · CVSS 3.3
A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
Published Jul 27, 2018 · Updated Aug 5, 2024
Medium · CVSS 4.5
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Published Jul 27, 2018 · Updated Aug 5, 2024
Low · CVSS 3.3
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.
Published Jul 27, 2018 · Updated Aug 5, 2024
Medium · CVSS 4.5
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
Published Jul 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.
Published Jul 20, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in The installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017, The self-extracting archive including the installer of MLIT DenshiSeikabutsuSakuseiShienKensa system Ver3.02 and earlier, distributed till June 20, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Self-extracting encrypted files created by AttacheCase ver.2.8.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Encrypted files in self-decryption format created by FileCapsule Deluxe Portable Ver.1.0.5.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Self-extracting encrypted files created by AttacheCase ver.3.2.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in FileCapsule Deluxe Portable Ver.1.0.5.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in FileCapsule Deluxe Portable Ver.1.0.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in FileCapsule Deluxe Portable Ver.2.0.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Encrypted files in self-decryption format created by FileCapsule Deluxe Portable Ver.1.0.4.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Encrypted files in self-decryption format created by FileCapsule Deluxe Portable Ver.2.0.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Self-extracting archive files created by Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Setup file of advance preparation for e-Tax software (WEB version) (1.17.1) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier uses hard-coded credentials, which may allow attackers to perform operations on device with administrative privileges.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to read arbitrary files via "File Transfer Web Service".
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier and Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier, Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier may allow remote attackers to access a non-documented developer screen to perform operations on device with administrative privileges.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Self-extracting archive files created by Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in EbidSettingChecker.exe (version 1.0.0.0) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in self-extracting archive files created by File Compact Ver.5 version 5.10 and earlier, Ver.6 version 6.02 and earlier, Ver.7 version 7.02 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1.01 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Douro Kouji Kanseizutou Check Program Ver3.1 (cdrw_checker_3.1.0.lzh) and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of PDF Digital Signature Plugin (G2.30) and earlier, distributed till June 29, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of CASL II simulator (self-extract format) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of QuickTime for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in Event Calendar WD prior to version 1.0.94 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Toshiba Home gateway HEM-GW16A firmware HEM-GW16A-FW-V1.2.0 and earlier. Toshiba Home gateway HEM-GW26A firmware HEM-GW26A-FW-V1.2.0 and earlier allows an attacker to bypass access restriction to change the administrator account password via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in Responsive Lightbox prior to version 1.7.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in WP-Members prior to version 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024