CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-17856

    Last Modified: 20 Apr 2025

    kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the lack of stack-pointer alignment enforcement.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2017-17857

    Last Modified: 20 Apr 2025

    The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable stack read operations.

    Published: 19 Dec 2017
    6.5
    Medium

    CVE-2017-17884

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function WriteOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted PNG image file.

    Published: 19 Dec 2017
    7.8
    High

    CVE-2018-5345

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.

    Published: 19 Dec 2017
    8.8
    High

    CVE-2017-15700

    Last Modified: 20 Apr 2025

    A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17105

    Last Modified: 20 Apr 2025

    Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cmd=iptest.cgi&-time="1504225666237"&-url=$(reboot) request.

    Published: 18 Dec 2017
    8.8
    High

    CVE-2017-11562

    Last Modified: 20 Apr 2025

    A Session Fixation Vulnerability exists in the MT4 Networks SenhaSegura Web Application 2.2.23.8 via login_if.php.

    Published: 18 Dec 2017
    9.1
    Critical

    CVE-2017-15524

    Last Modified: 20 Apr 2025

    The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.

    Published: 18 Dec 2017
    7.2
    High

    CVE-2017-15876

    Last Modified: 20 Apr 2025

    Unrestricted File Upload vulnerability in GPWeb 8.4.61 allows remote authenticated users to upload any type of file, including a PHP shell.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-15877

    Last Modified: 20 Apr 2025

    Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17107

    Last Modified: 20 Apr 2025

    Zivif PR115-204-P-RS V2.3.4.2103 web cameras contain a hard-coded cat1029 password for the root user. The SONIX operating system's setup renders this password unchangeable and it can be used to access the device via a TELNET session.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-15875

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Password Recovery in GPWeb 8.4.61 allows remote attackers to execute arbitrary SQL commands via the "checkemail" parameter.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-16949

    Last Modified: 20 Apr 2025

    An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and file-uploader/file-uploader-class.php. This allows the attacker to upload anything they want to the server, as demonstrated by an action=ap_file_upload_action&allowedExtensions[]=php request to /wp-admin/admin-ajax.php that results in a .php file upload and resultant PHP code execution.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17106

    Last Modified: 20 Apr 2025

    Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in requests to CGI pages.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17721

    Last Modified: 20 Apr 2025

    CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.

    Published: 18 Dec 2017
    5.4
    Medium

    CVE-2017-12630

    Last Modified: 20 Apr 2025

    In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, malicious user may obtain this information from Profile page afterwards.

    Published: 18 Dec 2017
    6.5
    Medium

    CVE-2017-14583

    Last Modified: 20 Apr 2025

    NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in SMB environments.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17643

    Last Modified: 20 Apr 2025

    FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17645

    Last Modified: 20 Apr 2025

    Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.

    Published: 18 Dec 2017
    6.1
    Medium

    CVE-2017-17649

    Last Modified: 20 Apr 2025

    Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17651

    Last Modified: 20 Apr 2025

    Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17734

    Last Modified: 20 Apr 2025

    CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17735

    Last Modified: 20 Apr 2025

    CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.

    Published: 18 Dec 2017
    6.1
    Medium

    CVE-2017-17737

    Last Modified: 20 Apr 2025

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.

    Published: 18 Dec 2017
    7.5
    High

    CVE-2017-17738

    Last Modified: 20 Apr 2025

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17739

    Last Modified: 20 Apr 2025

    The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17733

    Last Modified: 20 Apr 2025

    Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17731

    Last Modified: 20 Apr 2025

    DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.

    Published: 18 Dec 2017
    8.8
    High

    CVE-2017-17727

    Last Modified: 20 Apr 2025

    DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.

    Published: 18 Dec 2017
    9.8
    Critical

    CVE-2017-17730

    Last Modified: 20 Apr 2025

    DedeCMS through 5.7 has SQL Injection via the logo parameter to plus/flink_add.php.

    Published: 18 Dec 2017
    8.8
    High

    CVE-2017-15103

    Last Modified: 20 Apr 2025

    A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation.

    Published: 18 Dec 2017
    7.8
    High

    CVE-2017-15104

    Last Modified: 20 Apr 2025

    An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.

    Published: 18 Dec 2017
    7.5
    High

    CVE-2017-15124

    Last Modified: 21 Nov 2024

    VNC server implementation in Quick Emulator (QEMU) 2.11.0 and older was found to be vulnerable to an unbounded memory allocation issue, as it did not throttle the framebuffer updates sent to its client. If the client did not consume these updates, VNC server allocates growing memory to hold onto this data. A malicious remote VNC client could use this flaw to cause DoS to the server host.

    Published: 18 Dec 2017
    5.9
    Medium

    CVE-2017-17716

    Last Modified: 20 Apr 2025

    GitLab 9.4.x before 9.4.2 does not support LDAP SSL certificate verification, but a verify_certificates LDAP option was mentioned in the 9.4 release announcement. This issue occurred because code was not merged. This is related to use of the omniauth-ldap library and the gitlab_omniauth-ldap gem.

    Published: 17 Dec 2017
    9.8
    Critical

    CVE-2017-17717

    Last Modified: 20 Apr 2025

    Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.

    Published: 17 Dec 2017
    6.1
    Medium

    CVE-2017-16950

    Last Modified: 20 Apr 2025

    Cross - site scripting (XSS) vulnerability in UrBackup Server before 2.1.20 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 17 Dec 2017
    7.8
    High

    CVE-2017-16997

    Last Modified: 20 Apr 2025

    elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the "./" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.

    Published: 17 Dec 2017
    5.5
    Medium

    CVE-2018-1047

    Last Modified: 21 Nov 2024

    A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

    Published: 17 Dec 2017
    9.8
    Critical

    CVE-2017-17713

    Last Modified: 20 Apr 2025

    Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.

    Published: 16 Dec 2017
    6.1
    Medium

    CVE-2017-17714

    Last Modified: 20 Apr 2025

    Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /register lat parameter, the /register lon parameter, the /register org parameter, the /register query parameter, the /register region parameter, the /register regionName parameter, the /register timezone parameter, the /register vId parameter, the /register zip parameter, or the /tping id parameter.

    Published: 16 Dec 2017
    6.1
    Medium

    CVE-2017-14134

    Last Modified: 20 Apr 2025

    A Reflected XSS Vulnerability affects the forgotten password page of Maplesoft Maple T.A. 2016.0.6 (Customer Hosted) via the emailAddress parameter to passwordreset/PasswordReset.do, aka Open Bug Bounty ID OBB-286688.

    Published: 16 Dec 2017
    8.8
    High

    CVE-2017-17715

    Last Modified: 20 Apr 2025

    The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to tgnet.dat or tgnet.dat.bak.

    Published: 16 Dec 2017
    8.8
    High

    CVE-2017-14184

    Last Modified: 20 Apr 2025

    An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.

    Published: 15 Dec 2017
    5.9
    Medium

    CVE-2017-12373

    Last Modified: 20 Apr 2025

    A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-17699

    Last Modified: 20 Apr 2025

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-17700

    Last Modified: 20 Apr 2025

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-17701

    Last Modified: 20 Apr 2025

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.

    Published: 15 Dec 2017
    5.1
    Medium

    CVE-2017-17556

    Last Modified: 20 Apr 2025

    A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.

    Published: 15 Dec 2017
    6.1
    Medium

    CVE-2017-17698

    Last Modified: 20 Apr 2025

    Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-14101

    Last Modified: 20 Apr 2025

    A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for arbitrary file read access to the local file system as well as the transmittal of the application service's account hashed credentials to a remote attacker.

    Published: 15 Dec 2017