CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-6138

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the non-default "normalize URI" configuration options used in iRules and/or BIG-IP LTM policies.

    Published: 21 Dec 2017
    5.9
    Medium

    CVE-2017-6139

    Last Modified: 20 Apr 2025

    In F5 BIG-IP APM software version 13.0.0 and 12.1.2, under rare conditions, the BIG-IP APM system appends log details when responding to client requests. Details in the log file can vary; customers running debug mode logging with BIG-IP APM are at highest risk.

    Published: 21 Dec 2017
    8.1
    High

    CVE-2017-6164

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator and WebSafe software version 13.0.0, 12.0.0 - 12.1.2, 11.6.0 - 11.6.1 and 11.5.0 - 11.5.4, in some circumstances, Traffic Management Microkernel (TMM) does not properly handle certain malformed TLS1.2 records, which allows remote attackers to cause a denial-of-service (DoS) or possible remote command execution on the BIG-IP system.

    Published: 21 Dec 2017
    7.5
    High

    CVE-2017-6167

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM and WebSafe software version 13.0.0 and 12.1.0 - 12.1.2, race conditions in iControl REST may lead to commands being executed with different privilege levels than expected.

    Published: 21 Dec 2017
    7.5
    High

    CVE-2017-6132

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and Websafe software version 13.0.0, 12.0.0 to 12.1.2, 11.6.0 to 11.6.1 and 11.5.0 - 11.5.4, an undisclosed sequence of packets sent to BIG-IP High Availability state mirror listeners (primary and/or secondary IP) may cause TMM to restart.

    Published: 21 Dec 2017
    6.5
    Medium

    CVE-2017-6134

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0, 12.1.0 - 12.1.2 and 11.5.1 - 11.6.1, an undisclosed sequence of packets, sourced from an adjacent network may cause TMM to crash.

    Published: 21 Dec 2017
    5.9
    Medium

    CVE-2017-6136

    Last Modified: 20 Apr 2025

    In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, GTM, Link Controller, PEM and WebSafe software version 13.0.0 and 12.0.0 - 12.1.2, undisclosed traffic patterns sent to BIG-IP virtual servers, with the TCP Fast Open and Tail Loss Probe options enabled in the associated TCP profile, may cause a disruption of service to the Traffic Management Microkernel (TMM).

    Published: 21 Dec 2017
    7.5
    High

    CVE-2017-6140

    Last Modified: 20 Apr 2025

    On the BIG-IP 2000s, 2200s, 4000s, 4200v, i5600, i5800, i7600, i7800, i10600,i10800, and VIPRION 4450 blades, running version 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 or 12.1.2 of BIG-IP LTM, AAM, AFM, Analytics, ASM, DNS, GTM or PEM, an undisclosed sequence of packets sent to Virtual Servers with client or server SSL profiles may cause disruption of data plane services.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2015-7224

    Last Modified: 20 Apr 2025

    puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17030

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    6.8
    Medium

    CVE-2015-4100

    Last Modified: 20 Apr 2025

    Puppet Enterprise 3.7.x and 3.8.0 might allow remote authenticated users to manage certificates for arbitrary nodes by leveraging a client certificate trusted by the master, aka a "Certificate Authority Reverse Proxy Vulnerability."

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17031

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17027

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in FTP service in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17028

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in external device function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17029

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in login function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17032

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17033

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in password function in QNAP QTS version 4.2.6 build 20171026, 4.3.3.0378 build 20171117, 4.3.4.0387 (Beta 2) build 20171116 and earlier could allow remote attackers to execute arbitrary code on NAS devices.

    Published: 21 Dec 2017
    8.8
    High

    CVE-2017-17408

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within cevakrnl.xmd. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code under the context of SYSTEM. Was ZDI-CAN-5101.

    Published: 21 Dec 2017
    8.8
    High

    CVE-2017-17409

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within emulator 0x10A in cevakrnl.xmd. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before writing to memory. An attacker can leverage this vulnerability to execute code under the context of SYSTEM. Was ZDI-CAN-5102.

    Published: 21 Dec 2017
    8.8
    High

    CVE-2017-17410

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within emulator 0x102 in cevakrnl.xmd. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code under the context of SYSTEM. Was ZDI-CAN-5116.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17411

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

    Published: 21 Dec 2017
    8.8
    High

    CVE-2017-17831

    Last Modified: 20 Apr 2025

    GitHub Git LFS before 2.1.1 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, located on a "url =" line in a .lfsconfig file within a repository.

    Published: 21 Dec 2017
    4.8
    Medium

    CVE-2017-17828

    Last Modified: 20 Apr 2025

    Bus Booking Script has XSS via the results.php datepicker parameter or the admin/new_master.php spemail parameter.

    Published: 21 Dec 2017
    7.2
    High

    CVE-2017-17829

    Last Modified: 20 Apr 2025

    Bus Booking Script has SQL Injection via the admin/view_seatseller.php sp_id parameter or the admin/view_member.php memid parameter.

    Published: 21 Dec 2017
    6.8
    Medium

    CVE-2017-17830

    Last Modified: 20 Apr 2025

    Bus Booking Script has CSRF via admin/new_master.php.

    Published: 21 Dec 2017
    6.1
    Medium

    CVE-2017-17826

    Last Modified: 20 Apr 2025

    The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration&section=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it.

    Published: 21 Dec 2017
    4.9
    Medium

    CVE-2017-17822

    Last Modified: 20 Apr 2025

    The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

    Published: 21 Dec 2017
    4.9
    Medium

    CVE-2017-17823

    Last Modified: 20 Apr 2025

    The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

    Published: 21 Dec 2017
    4.9
    Medium

    CVE-2017-17824

    Last Modified: 20 Apr 2025

    The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.

    Published: 21 Dec 2017
    4.8
    Medium

    CVE-2017-17825

    Last Modified: 20 Apr 2025

    The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.

    Published: 21 Dec 2017
    8.8
    High

    CVE-2017-17827

    Last Modified: 20 Apr 2025

    Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.

    Published: 21 Dec 2017
    9.8
    Critical

    CVE-2017-17821

    Last Modified: 20 Apr 2025

    WTF/wtf/FastBitVector.h in WebKit, as distributed in Safari Technology Preview Release 46, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact because it calls the FastBitVectorWordOwner::resizeSlow function (in WTF/wtf/FastBitVector.cpp) for a purpose other than initializing a bitvector size, and resizeSlow mishandles cases where the old array length is greater than the new array length.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2020-10729

    Last Modified: 21 Nov 2024

    A flaw was found in the use of insufficiently random values in Ansible. Two random password lookups of the same length generate the equal value as the template caching action for the same file since no re-evaluation happens. The highest threat from this vulnerability would be that all passwords are exposed at once for the file. This flaw affects Ansible Engine versions before 2.9.6.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17815

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relationship between minimum and maximum parameter counts.

    Published: 21 Dec 2017
    6.5
    Medium

    CVE-2017-15125

    Last Modified: 21 Nov 2024

    A flaw was found in CloudForms before 5.9.0.22 in the self-service UI snapshot feature where the name field is not properly sanitized for HTML and JavaScript input. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. Please note that CSP (Content Security Policy) prevents exploitation of this XSS however not all browsers support CSP.

    Published: 21 Dec 2017
    7.5
    High

    CVE-2017-17818

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17810

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of arguments.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17811

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to CVE-2017-11111.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17812

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17816

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17817

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in asm/preproc.c that will cause a remote denial of service attack.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17813

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syntax errors.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17814

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17819

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with skip_white_ calls are not validated.

    Published: 21 Dec 2017
    5.5
    Medium

    CVE-2017-17820

    Last Modified: 20 Apr 2025

    In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.

    Published: 21 Dec 2017
    7.8
    High

    CVE-2017-17852

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops.

    Published: 21 Dec 2017
    6.5
    Medium

    CVE-2017-18273

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.

    Published: 21 Dec 2017
    6.5
    Medium

    CVE-2017-14387

    Last Modified: 20 Apr 2025

    The NFS service in EMC Isilon OneFS 8.1.0.0, 8.0.1.0 - 8.0.1.1, and 8.0.0.0 - 8.0.0.4 maintains default NFS export settings (including the NFS export security flavor for authentication) that can be leveraged by current and future NFS exports. This NFS service contained a flaw that did not properly propagate changes made to the default security flavor to all new and existing NFS exports that are configured to use default NFS export settings and that are mounted after those changes are made. This flaw may potentially allow NFS clients to access affected NFS exports using the default and potentially weaker security flavor even if a more secure one was selected to be used by the OneFS administrator, aka an "NFS Export Security Setting Fallback Vulnerability."

    Published: 20 Dec 2017
    7.5
    High

    CVE-2017-14385

    Last Modified: 20 Apr 2025

    An issue was discovered in EMC Data Domain DD OS 5.7 family, versions prior to 5.7.5.6; EMC Data Domain DD OS 6.0 family, versions prior to 6.0.2.9; EMC Data Domain DD OS 6.1 family, versions prior to 6.1.0.21; EMC Data Domain Virtual Edition 2.0 family, all versions; EMC Data Domain Virtual Edition 3.0 family, versions prior to 3.0 SP2 Update 1; and EMC Data Domain Virtual Edition 3.1 family, versions prior to 3.1 Update 2. EMC Data Domain DD OS contains a memory overflow vulnerability in SMBv1 which may potentially be exploited by an unauthenticated remote attacker. An attacker may completely shut down both the SMB service and active directory authentication. This may also allow remote code injection and execution.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17809

    Last Modified: 20 Apr 2025

    In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the arguments passed to the OpenVPN binary when executed. An attacker can abuse this vulnerability by forcing the VyprVPN application to load a malicious dynamic library every time a new connection is made.

    Published: 20 Dec 2017