CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-14875

    Last Modified: 21 Nov 2024

    In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a heap overread vulnerability exists.

    Published: 30 Mar 2018
    7.5
    High

    CVE-2017-15859

    Last Modified: 21 Nov 2024

    While processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE_DECR_DB vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE_DECR_DB contains fewer than 1 byte, in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-11 a buffer overrun occurs.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14883

    Last Modified: 21 Nov 2024

    In the function wma_unified_power_debug_stats_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-18, if the value param_buf->num_debug_register received from the FW command buffer is close to max of uint32, then the computation performed using this variable to calculate stats_registers_len may overflow to a smaller value leading to less than required memory allocated for power_stats_results and potentially a buffer overflow while copying the FW buffer to local buffer.

    Published: 30 Mar 2018
    5.3
    Medium

    CVE-2017-14891

    Last Modified: 21 Nov 2024

    In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the stack can get leaked due to an uninitialized variable.

    Published: 30 Mar 2018
    6.1
    Medium

    CVE-2018-1233

    Last Modified: 21 Nov 2024

    RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are affected by a cross-site scripting vulnerability. The attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.

    Published: 30 Mar 2018
    7.5
    High

    CVE-2017-11087

    Last Modified: 21 Nov 2024

    libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larger than the output buffer's actual size, leading to an information disclosure problem in the context of mediaserver.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14876

    Last Modified: 21 Nov 2024

    In msm_ispif_config_stereo() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-21, the parameter params->entries[i].vfe_intf comes from userspace without any bounds check which could potentially result in a kernel out-of-bounds write.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14877

    Last Modified: 21 Nov 2024

    While the IPA driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-08-31 is processing IOCTL commands there is no mutex lock of allocated memory. If one thread sends an ioctl cmd IPA_IOC_QUERY_RT_TBL_INDEX while another sends an ioctl cmd IPA_IOC_DEL_RT_RULE, a use-after-free condition may occur.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14881

    Last Modified: 21 Nov 2024

    While calling the IPA IOCTL handler for IPA_IOC_ADD_HDR_PROC_CTX in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-13, a use-after-free condition may potentially occur.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-14892

    Last Modified: 21 Nov 2024

    In the function msm_pcm_hw_params() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-19, the return value of q6asm_open_shared_io() is not checked properly potentially leading to a possible dangling pointer access.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-15823

    Last Modified: 21 Nov 2024

    In spectral_create_samp_msg() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-11, some values from firmware are not properly validated potentially leading to a buffer overflow.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-15826

    Last Modified: 21 Nov 2024

    Due to a race condition in MDSS rotator in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-20, a double free vulnerability may potentially exist when two threads free the same perf structures.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-15846

    Last Modified: 21 Nov 2024

    In the video_ioctl2() function in the camera driver in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-09-16, an untrusted pointer dereference may potentially occur.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-16614

    Last Modified: 21 Nov 2024

    SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugins/payment/weixin/lib/WxPay.tedatac.php fBill parameter.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-17766

    Last Modified: 21 Nov 2024

    In wma_peer_info_event_handler() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-03, the value of num_peers received from firmware is not properly validated so that an integer overflow vulnerability in the size of a buffer allocation may potentially lead to a buffer overflow.

    Published: 30 Mar 2018
    5.5
    Medium

    CVE-2017-17769

    Last Modified: 21 Nov 2024

    Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-17771

    Last Modified: 21 Nov 2024

    In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-02-12, an array out of bounds can occur.

    Published: 30 Mar 2018
    4.7
    Medium

    CVE-2017-9691

    Last Modified: 21 Nov 2024

    There is a race condition in Android for MSM, Firefox OS for MSM, and QRD Android that allows to access to already free'd memory in the debug message output functionality contained within the mobicore driver.

    Published: 30 Mar 2018
    5.5
    Medium

    CVE-2017-9693

    Last Modified: 21 Nov 2024

    The length of attribute value for STA_EXT_CAPABILITY in __wlan_hdd_change_station in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-06 being less than the actual lenth of StaParams.extn_capability results in a read for extra bytes when a memcpy is done from params->ext_capab to StaParams.extn_capability using the sizeof(StaParams.extn_capability).

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-9694

    Last Modified: 21 Nov 2024

    While parsing Netlink attributes in QCA_WLAN_VENDOR_ATTR_EXTSCAN_BSSID_HOTLIST_PARAMS_LOST_AP_SAMPLE_SIZE in qcacld 2.0 before 2017-05-16, a buffer overread could occur.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-15852

    Last Modified: 21 Nov 2024

    Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-9692

    Last Modified: 21 Nov 2024

    When an atomic commit is issued on a writeback panel with a NULL output_layer parameter in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-03, a NULL pointer dereference may potentially occur.

    Published: 30 Mar 2018
    7.8
    High

    CVE-2017-9723

    Last Modified: 21 Nov 2024

    The touchscreen driver synaptics_dsx in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-06-05, the size of a stack-allocated buffer can be set to a value which exceeds the size of the stack.

    Published: 30 Mar 2018
    5.5
    Medium

    CVE-2018-1234

    Last Modified: 21 Nov 2024

    RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows Named Pipe were not sufficient to prevent access by unauthorized users. The attacker with local access to the system can exploit this vulnerability to read configuration properties for the authentication agent.

    Published: 30 Mar 2018
    8
    High

    CVE-2018-5708

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the response (specifically, the configuration file restore_default), which is displayed in XML.

    Published: 30 Mar 2018
    7.5
    High

    CVE-2018-7171

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.

    Published: 30 Mar 2018
    6.5
    Medium

    CVE-2018-3817

    Last Modified: 21 Nov 2024

    When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2018-3822

    Last Modified: 21 Nov 2024

    X-Pack Security versions 6.2.0, 6.2.1, and 6.2.2 are vulnerable to a user impersonation attack via incorrect XML canonicalization and DOM traversal. An attacker might have been able to impersonate a legitimate user if the SAML Identity Provider allows for self registration with arbitrary identifiers and the attacker can register an account which an identifier that shares a suffix with a legitimate account. Both of those conditions must be true in order to exploit this flaw.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2018-9148

    Last Modified: 21 Nov 2024

    Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass authentication by listing a directory. NOTE: this can be exploited in conjunction with CVE-2018-7171 for remote authentication bypass within a product that uses My Cloud.

    Published: 30 Mar 2018
    7.5
    High

    CVE-2018-3740

    Last Modified: 21 Nov 2024

    A specially crafted HTML fragment can cause Sanitize gem for Ruby to allow non-whitelisted attributes to be used on a whitelisted HTML element.

    Published: 30 Mar 2018
    5.5
    Medium

    CVE-2018-9151

    Last Modified: 21 Nov 2024

    A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.

    Published: 30 Mar 2018
    5.4
    Medium

    CVE-2018-1390

    Last Modified: 21 Nov 2024

    IBM Financial Transaction Manager for Check Services for Multi-Platform 3.0, 3.0.2, and 3.0.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138221.

    Published: 30 Mar 2018
    8.8
    High

    CVE-2018-9134

    Last Modified: 21 Nov 2024

    file_manage_control.php in DedeCMS 5.7 has CSRF in an fmdo=rename action, as demonstrated by renaming an arbitrary file under uploads/userup to a .php file under the web root to achieve PHP code execution. This uses the oldfilename and newfilename parameters.

    Published: 30 Mar 2018
    6.1
    Medium

    CVE-2018-9147

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerabilities in version 7.5.7 of Gespage software allow remote attackers to inject arbitrary web script or HTML via the email, passwd, and repasswd parameters to webapp/users/user_reg.jsp.

    Published: 30 Mar 2018
    4
    Medium

    CVE-2017-1756

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.6 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 135856.

    Published: 30 Mar 2018
    3.1
    Low

    CVE-2017-1765

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.6 could allow an authenticated user with special privileges to reveal sensitive information about the application server. IBM X-Force ID: 136150.

    Published: 30 Mar 2018
    5.3
    Medium

    CVE-2017-1747

    Last Modified: 21 Nov 2024

    A specially crafted message could cause a denial of service in IBM WebSphere MQ 9.0, 9.0.0.1, 9.0.0.2, 9.0.1, 9.0.2, 9.0.3, and 9.0.4 applications consuming messages that it needs to perform data conversion on. IBM X-Force ID: 135520.

    Published: 30 Mar 2018
    5.4
    Medium

    CVE-2018-1384

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138135.

    Published: 30 Mar 2018
    4.3
    Medium

    CVE-2017-1705

    Last Modified: 21 Nov 2024

    IBM Security Privileged Identity Manager 2.1.0 contains left-over, sensitive information in page comments. While this information is not visible at first it can be obtained by viewing the page source. IBM X-Force ID: 134427.

    Published: 30 Mar 2018
    4.3
    Medium

    CVE-2017-1766

    Last Modified: 21 Nov 2024

    Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.

    Published: 30 Mar 2018
    5.4
    Medium

    CVE-2017-1767

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136152.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14912

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile [VERSION]: MDM9206, MDM9607, MDM9650, MSM8909W, SD 200, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 835, the attributes of buffers in Secure Display were not marked properly.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14915

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14911

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile, Snapdragon Automobile APQ8096AU, MDM9206, MDM9650, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 625, SD 650/52, SD 820, SD 835, it is possible for the XBL loader to skip the authentication of device config.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-11010

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14906

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, PKCS7 padding is not supported by the crypto storage APIs.

    Published: 30 Mar 2018
    6.5
    Medium

    CVE-2017-9681

    Last Modified: 21 Nov 2024

    In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel memory address is passed from userspace through iris_vidioc_s_ext_ctrls ioctl, it will print kernel address data. A user could set it to an arbitrary kernel address, hence information disclosure (for kernel) could occur.

    Published: 30 Mar 2018
    9.8
    Critical

    CVE-2017-14913

    Last Modified: 21 Nov 2024

    In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, SD 625, SD 650/52, SD 835, SD 845, DDR address input validation is being improperly truncated.

    Published: 30 Mar 2018
    6.1
    Medium

    CVE-2018-5799

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine ServiceDesk Plus before 9403, an XSS issue allows an attacker to run arbitrary JavaScript via a /api/request/?OPERATION_NAME= URI, aka SD-69139.

    Published: 30 Mar 2018
    6.5
    Medium

    CVE-2018-9132

    Last Modified: 21 Nov 2024

    libming 0.4.8 has a NULL pointer dereference in the getInt function of the decompile.c file. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted swf file.

    Published: 30 Mar 2018