CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-1000427

    Last Modified: 21 Nov 2024

    marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

    Published: 2 Jan 2018
    8
    High

    CVE-2017-1000432

    Last Modified: 21 Nov 2024

    Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000437

    Last Modified: 21 Nov 2024

    Creolabs Gravity 1.0 contains a stack based buffer overflow in the operator_string_add function, resulting in remote code execution.

    Published: 2 Jan 2018
    8.3
    High

    CVE-2017-1000438

    Last Modified: 21 Nov 2024

    In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying filesystem, then manipulate the user's data.

    Published: 2 Jan 2018
    6.1
    Medium

    CVE-2017-1000426

    Last Modified: 21 Nov 2024

    MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.

    Published: 2 Jan 2018
    6.1
    Medium

    CVE-2017-1000431

    Last Modified: 21 Nov 2024

    eZ Systems eZ Publish version 5.4.0 to 5.4.9, and 5.3.12 and older, is vulnerable to an XSS issue in the search module, resulting in a risk of attackers injecting scripts which may e.g. steal authentication credentials.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000430

    Last Modified: 21 Nov 2024

    rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions

    Published: 2 Jan 2018
    4.3
    Medium

    CVE-2017-1000424

    Last Modified: 21 Nov 2024

    Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000423

    Last Modified: 21 Nov 2024

    b2evolution version 6.6.0 - 6.8.10 is vulnerable to input validation (backslash and single quote escape) in basic install functionality resulting in unauthenticated attacker gaining PHP code execution on the victim's setup.

    Published: 2 Jan 2018
    7.5
    High

    CVE-2017-1000419

    Last Modified: 21 Nov 2024

    phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

    Published: 2 Jan 2018
    7.5
    High

    CVE-2017-1000420

    Last Modified: 21 Nov 2024

    Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000421

    Last Modified: 21 Nov 2024

    Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

    Published: 2 Jan 2018
    4.8
    Medium

    CVE-2017-1000457

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000458

    Last Modified: 21 Nov 2024

    Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.

    Published: 2 Jan 2018
    7.8
    High

    CVE-2017-1000451

    Last Modified: 21 Nov 2024

    fs-git is a file system like api for git repository. The fs-git version 1.0.1 module relies on child_process.exec, however, the buildCommand method used to construct exec strings does not properly sanitize data and is vulnerable to command injection across all methods that use it and call exec.

    Published: 2 Jan 2018
    7.5
    High

    CVE-2017-1000412

    Last Modified: 21 Nov 2024

    Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.

    Published: 2 Jan 2018
    5.9
    Medium

    CVE-2017-1000413

    Last Modified: 21 Nov 2024

    Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.

    Published: 2 Jan 2018
    7.5
    High

    CVE-2017-1000448

    Last Modified: 21 Nov 2024

    Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.

    Published: 2 Jan 2018
    Unknown

    CVE-2017-1000449

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 2 Jan 2018
    7.5
    High

    CVE-2017-1000452

    Last Modified: 21 Nov 2024

    An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000453

    Last Modified: 21 Nov 2024

    CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.

    Published: 2 Jan 2018
    7.8
    High

    CVE-2017-1000454

    Last Modified: 21 Nov 2024

    CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1

    Published: 2 Jan 2018
    5.5
    Medium

    CVE-2017-1000455

    Last Modified: 21 Nov 2024

    GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in "the store", violating a fundamental security assumption of GNU Guix.

    Published: 2 Jan 2018
    4.3
    Medium

    CVE-2017-1557

    Last Modified: 21 Nov 2024

    IBM WebSphere MQ 8.0 and 9.0 could allow an authenticated user with authority to send a specially crafted request that could cause a channel process to cease processing further requests. IBM X-Force ID: 131547.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-1000444

    Last Modified: 21 Nov 2024

    Eleix Openhacker version 0.1.47 is vulnerable to an SQL injection in the account registration and login component resulting in information disclosure and remote code execution

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-17098

    Last Modified: 21 Nov 2024

    The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

    Published: 2 Jan 2018
    9.8
    Critical

    CVE-2017-17097

    Last Modified: 21 Nov 2024

    gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

    Published: 2 Jan 2018
    5.4
    Medium

    CVE-2017-1000442

    Last Modified: 21 Nov 2024

    Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace

    Published: 2 Jan 2018
    6.1
    Medium

    CVE-2017-1000443

    Last Modified: 21 Nov 2024

    Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.

    Published: 2 Jan 2018
    7.1
    High

    CVE-2017-9966

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. By replacing certain files, an unauthorized user can obtain system privileges and the inserted code would execute at an elevated privilege level.

    Published: 2 Jan 2018
    6.1
    Medium

    CVE-2017-18015

    Last Modified: 21 Nov 2024

    The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.

    Published: 2 Jan 2018
    6.9
    Medium

    CVE-2017-9964

    Last Modified: 21 Nov 2024

    A Path Traversal issue was discovered in Schneider Electric Pelco VideoXpert Enterprise all versions prior to 2.1. By sniffing communications, an unauthorized person can execute a directory traversal attack resulting in authentication bypass or session hijack.

    Published: 2 Jan 2018
    5.8
    Medium

    CVE-2017-9965

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Schneider Electric's Pelco VideoXpert Enterprise versions 2.0 and prior. Using a directory traversal attack, an unauthorized person can view web server files.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4756

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4757

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4758

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4759

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4760

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4761

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4762

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4763

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4764

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4765

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4766

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4767

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4768

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4770

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4771

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4772

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018
    Unknown

    CVE-2018-4773

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 2 Jan 2018