Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2017
Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.
CVSS Score
7.5
EPSS Score
0.003
Published
2017-04-13
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.
CVSS Score
8.8
EPSS Score
0.032
Published
2017-04-13
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.
CVSS Score
6.1
EPSS Score
0.083
Published
2017-04-13
Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) <input:hidden> or (6) <bean:message> tags.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-04-13
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
CVSS Score
9.8
EPSS Score
0.787
Published
2017-04-13
Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.
CVSS Score
5.3
EPSS Score
0.002
Published
2017-04-13
Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2015-8864.
CVSS Score
6.1
EPSS Score
0.007
Published
2017-04-13
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
CVSS Score
9.8
EPSS Score
0.005
Published
2017-04-13
handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).
CVSS Score
7.5
EPSS Score
0.082
Published
2017-04-13
SAP HANA DB 1.00.73.00.389160 allows remote attackers to execute arbitrary code via vectors involving the audit logs, aka SAP Security Note 2170806.
CVSS Score
9.8
EPSS Score
0.065
Published
2017-04-13


Contact Us

Shodan ® - All rights reserved