CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-17792

    Last Modified: 20 Apr 2025

    Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a comment.

    Published: 20 Dec 2017
    7.5
    High

    CVE-2017-17793

    Last Modified: 20 Apr 2025

    Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17796

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x827300A4.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17797

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83000058.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17798

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.42, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8273A0A0, a different vulnerability than CVE-2017-17800.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17799

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x82730068.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17800

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8273A0A0, a different vulnerability than CVE-2017-17798.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17801

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x8273E060.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17804

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83000084.

    Published: 20 Dec 2017
    Unknown

    CVE-2017-17781

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2017-17794

    Last Modified: 20 Apr 2025

    validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address field.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17795

    Last Modified: 20 Apr 2025

    In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83000088.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-17803

    Last Modified: 20 Apr 2025

    In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x82736068, a different vulnerability than CVE-2017-17475.

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2017-17779

    Last Modified: 20 Apr 2025

    Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.

    Published: 20 Dec 2017
    8.8
    High

    CVE-2017-17774

    Last Modified: 20 Apr 2025

    admin/configuration.php in Piwigo 2.9.2 has CSRF.

    Published: 20 Dec 2017
    6.1
    Medium

    CVE-2017-17775

    Last Modified: 20 Apr 2025

    Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.

    Published: 20 Dec 2017
    5.3
    Medium

    CVE-2017-17776

    Last Modified: 20 Apr 2025

    Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.

    Published: 20 Dec 2017
    4.8
    Medium

    CVE-2017-17778

    Last Modified: 20 Apr 2025

    Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.

    Published: 20 Dec 2017
    9.8
    Critical

    CVE-2017-17777

    Last Modified: 20 Apr 2025

    Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.

    Published: 20 Dec 2017
    6.1
    Medium

    CVE-2017-17780

    Last Modified: 20 Apr 2025

    The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found in the following WordPress plugins: Clockwork Free and Paid SMS Notifications 2.0.3, Two-Factor Authentication - Clockwork SMS 1.0.2, Booking Calendar - Clockwork SMS 1.0.5, Contact Form 7 - Clockwork SMS 2.3.0, Fast Secure Contact Form - Clockwork SMS 2.1.2, Formidable - Clockwork SMS 1.0.2, Gravity Forms - Clockwork SMS 2.2, and WP e-Commerce - Clockwork SMS 2.0.5.

    Published: 20 Dec 2017
    6.5
    Medium

    CVE-2017-17887

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function GetImagePixelCache in magick/cache.c, which allows attackers to cause a denial of service via a crafted MNG image file that is processed by ReadOneMNGImage.

    Published: 20 Dec 2017
    3.3
    Low

    CVE-2018-18386

    Last Modified: 21 Nov 2024

    drivers/tty/n_tty.c in the Linux kernel before 4.14.11 allows local attackers (who are able to access pseudo terminals) to hang/block further usage of any pseudo terminal devices due to an EXTPROC versus ICANON confusion in TIOCINQ.

    Published: 20 Dec 2017
    7.8
    High

    CVE-2017-18075

    Last Modified: 21 Nov 2024

    crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.

    Published: 20 Dec 2017
    6.1
    Medium

    CVE-2017-17837

    Last Modified: 21 Nov 2024

    The Apache DeltaSpike-JSF 1.8.0 module has a XSS injection leak in the windowId handling. The default size of the windowId get's cut off after 10 characters (by default), so the impact might be limited. A fix got applied and released in Apache deltaspike-1.8.1.

    Published: 20 Dec 2017
    7.1
    High

    CVE-2017-18018

    Last Modified: 9 Jun 2025

    In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

    Published: 20 Dec 2017
    7.5
    High

    CVE-2017-17763

    Last Modified: 20 Apr 2025

    SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection mechanism for file transfer, which makes it easier for remote attackers to send crafted files, as demonstrated by APK injection.

    Published: 19 Dec 2017
    9.8
    Critical

    CVE-2017-17761

    Last Modified: 20 Apr 2025

    An issue was discovered on Ichano AtHome IP Camera devices. The device runs the "noodles" binary - a service on port 1300 that allows a remote (LAN) unauthenticated user to run arbitrary commands. This binary requires the "system" XML element for specifying the command. For example, a <system>id</system> command results in a <system_ack>ok</system_ack> response.

    Published: 19 Dec 2017
    6.1
    Medium

    CVE-2017-17719

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.

    Published: 19 Dec 2017
    6.1
    Medium

    CVE-2017-17744

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.

    Published: 19 Dec 2017
    6.1
    Medium

    CVE-2017-17753

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.

    Published: 19 Dec 2017
    6.5
    Medium

    CVE-2017-16786

    Last Modified: 20 Apr 2025

    The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.

    Published: 19 Dec 2017
    8.8
    High

    CVE-2017-15048

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

    Published: 19 Dec 2017
    8.8
    High

    CVE-2017-15049

    Last Modified: 20 Apr 2025

    The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

    Published: 19 Dec 2017
    7.5
    High

    CVE-2017-17088

    Last Modified: 20 Apr 2025

    The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service.

    Published: 19 Dec 2017
    9.8
    Critical

    CVE-2017-17759

    Last Modified: 20 Apr 2025

    Conarc iChannel allows remote attackers to obtain sensitive information, modify the configuration, or cause a denial of service (by deleting the configuration) via a wc.dll?wwMaint~EditConfig request (which reaches an older version of a West Wind Web Connection HTTP service).

    Published: 19 Dec 2017
    8.8
    High

    CVE-2017-17757

    Last Modified: 20 Apr 2025

    TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.

    Published: 19 Dec 2017
    8.8
    High

    CVE-2017-17758

    Last Modified: 20 Apr 2025

    TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.

    Published: 19 Dec 2017
    5.5
    Medium

    CVE-2018-5750

    Last Modified: 21 Nov 2024

    The acpi_smbus_hc_add function in drivers/acpi/sbshc.c in the Linux kernel through 4.14.15 allows local users to obtain sensitive address information by reading dmesg data from an SBS HC printk call.

    Published: 19 Dec 2017
    5.5
    Medium

    CVE-2017-17788

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17853

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect BPF_RSH signed bounds calculations.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17784

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17785

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17786

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17789

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17854

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmetic.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17855

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging improper use of pointers in place of scalars.

    Published: 19 Dec 2017
    6.5
    Medium

    CVE-2017-18022

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.

    Published: 19 Dec 2017
    4.7
    Medium

    CVE-2017-15129

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17787

    Last Modified: 20 Apr 2025

    In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.

    Published: 19 Dec 2017
    9.8
    Critical

    CVE-2017-17790

    Last Modified: 20 Apr 2025

    The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument beginning with a '|' character, a different vulnerability than CVE-2017-17405. NOTE: situations with untrusted input may be highly unlikely.

    Published: 19 Dec 2017