CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-17849

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.

    Published: 24 Dec 2017
    8.8
    High

    CVE-2017-17891

    Last Modified: 20 Apr 2025

    Readymade Video Sharing Script has CSRF via user-profile-edit.php.

    Published: 24 Dec 2017
    8.8
    High

    CVE-2017-17894

    Last Modified: 20 Apr 2025

    Readymade Job Site Script has CSRF via the /job URI.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17895

    Last Modified: 20 Apr 2025

    Readymade Job Site Script has SQL Injection via the location_name array parameter to the /job URI.

    Published: 24 Dec 2017
    6.1
    Medium

    CVE-2017-17896

    Last Modified: 20 Apr 2025

    Readymade Job Site Script has XSS via the keyword parameter to the /job URI.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17897

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Dec 2017
    7.5
    High

    CVE-2017-17898

    Last Modified: 20 Apr 2025

    Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17899

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.

    Published: 24 Dec 2017
    8.8
    High

    CVE-2017-17888

    Last Modified: 20 Apr 2025

    cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gavazzi SIU-DLG, AEDILIS SMART-1, SYXTHSENSE WebBiter, ABB SREA, and ASCON DY WebServer devices, allows remote authenticated users to execute arbitrary OS commands via crafted multipart/form-data content, a different vulnerability than CVE-2017-9097.

    Published: 24 Dec 2017
    6.1
    Medium

    CVE-2017-17859

    Last Modified: 20 Apr 2025

    Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17878

    Last Modified: 20 Apr 2025

    An issue was discovered in Valve Steam Link build 643. Root passwords longer than 8 characters are truncated because of the default use of DES (aka the CONFIG_FEATURE_DEFAULT_PASSWD_ALGO="des" setting).

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17877

    Last Modified: 20 Apr 2025

    An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17871

    Last Modified: 20 Apr 2025

    The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17873

    Last Modified: 20 Apr 2025

    Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.

    Published: 24 Dec 2017
    8.8
    High

    CVE-2017-17874

    Last Modified: 20 Apr 2025

    Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-18269

    Last Modified: 21 Nov 2024

    An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being produced by the copy operation. This may disclose information to context-dependent attackers, or result in a denial of service, or, possibly, code execution.

    Published: 24 Dec 2017
    9.8
    Critical

    CVE-2017-17872

    Last Modified: 20 Apr 2025

    The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.

    Published: 24 Dec 2017
    8.8
    High

    CVE-2017-17879

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.

    Published: 24 Dec 2017
    7.8
    High

    CVE-2017-18078

    Last Modified: 21 Nov 2024

    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

    Published: 24 Dec 2017
    6.1
    Medium

    CVE-2017-17868

    Last Modified: 20 Apr 2025

    In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.

    Published: 23 Dec 2017
    6.1
    Medium

    CVE-2017-17869

    Last Modified: 20 Apr 2025

    The mgl-instagram-gallery plugin for WordPress has XSS via the single-gallery.php media parameter.

    Published: 23 Dec 2017
    9.8
    Critical

    CVE-2017-17870

    Last Modified: 20 Apr 2025

    The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.

    Published: 23 Dec 2017
    8.1
    High

    CVE-2017-16897

    Last Modified: 20 Apr 2025

    A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sign the full SAML response (e.g., only signs the assertion within the response).

    Published: 23 Dec 2017
    7.8
    High

    CVE-2017-17866

    Last Modified: 20 Apr 2025

    pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.

    Published: 23 Dec 2017
    7.8
    High

    CVE-2017-17863

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly have unspecified other impact.

    Published: 23 Dec 2017
    7.5
    High

    CVE-2017-14022

    Last Modified: 20 Apr 2025

    An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver service), causing the service to either stall or terminate.

    Published: 23 Dec 2017
    5.5
    Medium

    CVE-2017-17862

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users for denial of service.

    Published: 23 Dec 2017
    7.5
    High

    CVE-2017-17850

    Last Modified: 20 Apr 2025

    An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP messages create a dialog in Asterisk. Those SIP messages must contain a contact header. For those messages, if the header was not present and the PJSIP channel driver was used, Asterisk would crash. The severity of this vulnerability is somewhat mitigated if authentication is enabled. If authentication is enabled, a user would have to first be authorized before reaching the crash point.

    Published: 23 Dec 2017
    3.3
    Low

    CVE-2017-17864

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."

    Published: 23 Dec 2017
    5.9
    Medium

    CVE-2017-17843

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as demonstrated by a modified Full Name field and a homograph attack, aka TBE-01-002.

    Published: 22 Dec 2017
    6.5
    Medium

    CVE-2017-17844

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt that block and then send it back to the attacker as quoted text, aka the TBE-01-005 "replay" issue.

    Published: 22 Dec 2017
    7.3
    High

    CVE-2017-17845

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-17846

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-17847

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9. Signature spoofing is possible because the UI does not properly distinguish between an attachment signature, and a signature that applies to the entire containing message, aka TBE-01-021. This is demonstrated by an e-mail message with an attachment that is a signed e-mail message in message/rfc822 format.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-17848

    Last Modified: 20 Apr 2025

    An issue was discovered in Enigmail before 1.9.9. In a variant of CVE-2017-17847, signature spoofing is possible for multipart/related messages because a signed message part can be referenced with a cid: URI but not actually displayed. In other words, the entire containing message appears to be signed, but the recipient does not see any of the signed text.

    Published: 22 Dec 2017
    5.4
    Medium

    CVE-2017-17832

    Last Modified: 20 Apr 2025

    ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).

    Published: 22 Dec 2017
    8.8
    High

    CVE-2017-15308

    Last Modified: 20 Apr 2025

    Huawei iReader app before 8.0.2.301 has an input validation vulnerability due to insufficient validation on the URL used for loading network data. An attacker can control app access and load malicious websites created by the attacker, and the code in webpages would be loaded and run.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-15324

    Last Modified: 20 Apr 2025

    Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending malformed NQA packets to the target device. Successful exploitation could make the device restart.

    Published: 22 Dec 2017
    2.3
    Low

    CVE-2017-15307

    Last Modified: 20 Apr 2025

    Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulnerability due to improper authorization configuration on specific device information.

    Published: 22 Dec 2017
    6.5
    Medium

    CVE-2017-15310

    Last Modified: 20 Apr 2025

    Huawei iReader app before 8.0.2.301 has an arbitrary file deletion vulnerability due to the lack of input validation. An attacker can exploit this vulnerability to delete specific files from the SD card.

    Published: 22 Dec 2017
    8.8
    High

    CVE-2017-15311

    Last Modified: 20 Apr 2025

    The baseband modules of Mate 10, Mate 10 Pro, Mate 9, Mate 9 Pro Huawei smart phones with software before ALP-AL00 8.0.0.120(SP2C00), before BLA-AL00 8.0.0.120(SP2C00), before MHA-AL00B 8.0.0.334(C00), and before LON-AL00B 8.0.0.334(C00) have a stack overflow vulnerability due to the lack of parameter validation. An attacker could send malicious packets to the smart phones within radio range by special wireless device, which leads stack overflow when the baseband module handles these packets. The attacker could exploit this vulnerability to perform a denial of service attack or remote code execution in baseband module.

    Published: 22 Dec 2017
    5.4
    Medium

    CVE-2017-15312

    Last Modified: 20 Apr 2025

    Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote authenticated attacker could exploit this vulnerability to inject malicious scripts in the affected device.

    Published: 22 Dec 2017
    8.8
    High

    CVE-2017-15313

    Last Modified: 20 Apr 2025

    Huawei SmartCare V200R003C10 has a CSV injection vulnerability. An remote authenticated attacker could inject malicious CSV expression to the affected device.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-15317

    Last Modified: 20 Apr 2025

    AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR150-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR160 V200R006C10, V200R006C12, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR200 V200R006C10, V200R007C00, V200R007C01, V200R008C20, V200R008C30; AR200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR2200 V200R006C10, V200R006C13, V200R006C16, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR2200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR3200 V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30; AR510 V200R006C10, V200R006C12, V200R006C13, V200R006C15, V200R006C16, V200R006C17, V200R007C00, V200R008C20, V200R008C30; SRG1300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG2300 V200R006C10, V200R007C00, V200R007C02, V200R008C20, V200R008C30; SRG3300 V200R006C10, V200R007C00, V200R008C20, V200R008C30 have an input validation vulnerability in Huawei multiple products. Due to the insufficient input validation, an unauthenticated, remote attacker may craft a malformed Stream Control Transmission Protocol (SCTP) packet and send it to the device, causing the device to read out of bounds and restart.

    Published: 22 Dec 2017
    7.8
    High

    CVE-2017-15316

    Last Modified: 20 Apr 2025

    The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and causes a system crash or arbitrary code execution.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-15318

    Last Modified: 20 Apr 2025

    RP200 V500R002C00, V600R006C00; TE30 V100R001C10, V500R002C00, V600R006C00; TE40 V500R002C00, V600R006C00; TE50 V500R002C00, V600R006C00; TE60 V100R001C10, V500R002C00, V600R006C00 have an out-of-bounds read vulnerabilities in some Huawei products. Due to insufficient input validation, a remote attacker could exploit these vulnerabilities by sending specially crafted SS7 related packets to the target devices. Successful exploit will cause out-of-bounds read and possibly crash the system.

    Published: 22 Dec 2017
    3.7
    Low

    CVE-2017-15321

    Last Modified: 20 Apr 2025

    Huawei FusionSphere OpenStack V100R006C000SPC102 (NFV) has an information leak vulnerability due to the use of a low version transmission protocol by default. An attacker could intercept packets transferred by a target device. Successful exploit could cause an information leak.

    Published: 22 Dec 2017
    6.5
    Medium

    CVE-2017-15322

    Last Modified: 20 Apr 2025

    Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient input validation. An attacker could exploit this vulnerability by sending specially crafted NFC messages to the target device. Successful exploit could make a service crash.

    Published: 22 Dec 2017
    7.5
    High

    CVE-2017-15328

    Last Modified: 20 Apr 2025

    Huawei HG8245H version earlier than V300R018C00SPC110 has an authentication bypass vulnerability. An attacker can access a specific URL of the affect product. Due to improper verification of the privilege, successful exploitation may cause information leak.

    Published: 22 Dec 2017
    7.1
    High

    CVE-2017-15309

    Last Modified: 20 Apr 2025

    Huawei iReader app before 8.0.2.301 has a path traversal vulnerability due to insufficient validation on file storage paths. An attacker can exploit this vulnerability to store downloaded malicious files in an arbitrary directory.

    Published: 22 Dec 2017