Skip to main content

CWE archive

CWE-17 CVEs

Programmatic archive

165 CVEs tagged with CWE-1712 Critical, 45 High, 92 Medium, 16 Low, 0 Unrated.

CVE-2020-3222

Published Jun 3, 2020

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass access control restrictions on an aff…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10075

Published Jan 19, 2017

The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10142

Published Jan 14, 2017

An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all ven…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-3721

Published May 17, 2016

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5229

Published Apr 8, 2016

The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to…

CVSS 7.5 · High

CVE-2016-1640

Published Mar 6, 2016

The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2314

Published Feb 15, 2016

GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to cause a denial of service (device outage) by using the FTP…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1940

Published Jan 31, 2016

Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent proce…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1571

Published Jan 22, 2016

The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8027

Published Jan 2, 2016

Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a de…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-7410

Published Jan 1, 2016

The Health Check tool in IBM Sterling B2B Integrator 5.2 does not properly use cookies in conjunction with HTTPS sessions, which allows man-in-the-middle attackers to obtain sensi…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4943

Published Jan 1, 2016

IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulne…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4941

Published Jan 1, 2016

IBM WebSphere MQ Light 1.x before 1.0.2 mishandles abbreviated TLS handshakes, which allows remote attackers to cause a denial of service (MQXR service crash) via unspecified vect…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7793

Published Dec 30, 2015

Corega CG-WLBARAGM devices provide an open proxy service, which allows remote attackers to trigger outbound network traffic via unspecified vectors.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8340

Published Dec 17, 2015

The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly release locks, which might allow guest OS administrators to cause a denial of service…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7045

Published Dec 11, 2015

Keychain Access in Apple OS X before 10.11.2 and tvOS before 9.1 improperly interacts with Keychain Agent, which allows attackers to spoof the Keychain Server via unspecified vect…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0859

Published Dec 3, 2015

The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes argum…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8216

Published Nov 17, 2015

The ljpeg_decode_yuv_scan function in libavcodec/mjpegdec.c in FFmpeg before 2.8.2 omits certain width and height checks, which allows remote attackers to cause a denial of servic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 165 CVEsPage 1 of 7