CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-16787

    Last Modified: 20 Apr 2025

    The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read arbitrary files by leveraging failure to restrict URL access.

    Published: 15 Dec 2017
    7.2
    High

    CVE-2017-16788

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the "Upload Groupkey" functionality in the Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with Admin-User access to write to arbitrary files and consequently gain root privileges by uploading a file, as demonstrated by storing a file in the cron.d directory.

    Published: 15 Dec 2017
    8.1
    High

    CVE-2017-16776

    Last Modified: 20 Apr 2025

    Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, which is now a Change Healthcare company. The attacker must send a malicious HTTP GET request to exploit the vulnerability. The vulnerability allows an attacker to bypass authentication and escalate privileges of valid users. An unauthenticated attacker can exploit the vulnerability and be granted limited access to other accounts. An authenticated attacker can exploit the vulnerability and be granted access reserved for higher privilege users.

    Published: 15 Dec 2017
    4.8
    Medium

    CVE-2017-15890

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.

    Published: 15 Dec 2017
    9.1
    Critical

    CVE-2017-14090

    Last Modified: 20 Apr 2025

    A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3192

    Last Modified: 20 Apr 2025

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 do not sufficiently protect administrator credentials. The tools_admin.asp page discloses the administrator password in base64 encoding in the returned web page. A remote attacker with access to this page (potentially through a authentication bypass such as CVE-2017-3191) may obtain administrator credentials for the device.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-10904

    Last Modified: 20 Apr 2025

    Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 15 Dec 2017
    5.3
    Medium

    CVE-2017-10905

    Last Modified: 20 Apr 2025

    A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

    Published: 15 Dec 2017
    7.8
    High

    CVE-2017-11397

    Last Modified: 20 Apr 2025

    A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.

    Published: 15 Dec 2017
    7.5
    High

    CVE-2017-14091

    Last Modified: 20 Apr 2025

    A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.

    Published: 15 Dec 2017
    8.8
    High

    CVE-2017-14092

    Last Modified: 20 Apr 2025

    The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user browses an attacker-controlled domain.

    Published: 15 Dec 2017
    6.1
    Medium

    CVE-2017-14093

    Last Modified: 20 Apr 2025

    The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.

    Published: 15 Dec 2017
    8.1
    High

    CVE-2017-3194

    Last Modified: 20 Apr 2025

    Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3186

    Last Modified: 20 Apr 2025

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take complete control of a device using default admin credentials.

    Published: 15 Dec 2017
    8.8
    High

    CVE-2017-3193

    Last Modified: 20 Apr 2025

    Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overflow vulnerability in the web administration interface HNAP service.

    Published: 15 Dec 2017
    7.5
    High

    CVE-2017-3190

    Last Modified: 20 Apr 2025

    Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3191

    Last Modified: 20 Apr 2025

    D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as to access some administrator-only pages such as tools_admin.asp without credentials.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3184

    Last Modified: 20 Apr 2025

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability by directly accessing the http://x.x.x.x/setup/setup_maintain_firmware-default.html page. This will allow an attacker to perform a factory reset on the device, leading to a denial of service condition or the ability to make use of default credentials (CVE-2017-3186).

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3185

    Last Modified: 20 Apr 2025

    ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensitive information such as user account name and password, which can expose that information through the browser's history, referrers, web logs, and other sources.

    Published: 15 Dec 2017
    9.8
    Critical

    CVE-2017-3195

    Last Modified: 20 Apr 2025

    Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.

    Published: 15 Dec 2017
    7.8
    High

    CVE-2017-3196

    Last Modified: 20 Apr 2025

    PCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory outside of its typical bounds on the driver's receipt of network packets. Local attackers can exploit this issue to execute arbitrary code with SYSTEM privileges.

    Published: 15 Dec 2017
    β€”
    Unknown

    CVE-2017-1000384

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-16355. Reason: This candidate is a reservation duplicate of CVE-2017-16355. Notes: All CVE users should reference CVE-2017-16355 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Dec 2017
    8.8
    High

    CVE-2017-17670

    Last Modified: 20 Apr 2025

    In VideoLAN VLC media player through 2.2.8, there is a type conversion vulnerability in modules/demux/mp4/libmp4.c in the MP4 demux module leading to a invalid free, because the type of a box may be changed between a read operation and a free operation.

    Published: 15 Dec 2017
    4.3
    Medium

    CVE-2017-17693

    Last Modified: 20 Apr 2025

    Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.

    Published: 15 Dec 2017
    5.4
    Medium

    CVE-2017-17694

    Last Modified: 20 Apr 2025

    Techno - Portfolio Management Panel through 2017-11-16 allows XSS via the panel/search.php s parameter.

    Published: 15 Dec 2017
    8.8
    High

    CVE-2017-17695

    Last Modified: 20 Apr 2025

    Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.

    Published: 15 Dec 2017
    4.3
    Medium

    CVE-2017-17696

    Last Modified: 20 Apr 2025

    Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php.

    Published: 15 Dec 2017
    8.6
    High

    CVE-2017-17697

    Last Modified: 20 Apr 2025

    The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

    Published: 15 Dec 2017
    5.5
    Medium

    CVE-2017-18344

    Last Modified: 21 Nov 2024

    The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allows userspace applications to read arbitrary kernel memory (on a kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE).

    Published: 15 Dec 2017
    8.8
    High

    CVE-2017-5264

    Last Modified: 20 Apr 2025

    Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.

    Published: 14 Dec 2017
    7.5
    High

    CVE-2016-10703

    Last Modified: 20 Apr 2025

    A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and crash a server by passing a maliciously crafted string.

    Published: 14 Dec 2017
    8.1
    High

    CVE-2017-7344

    Last Modified: 20 Apr 2025

    A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog thereby popping up when the "VPN before logon" feature is enabled and an untrusted certificate chain.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17516

    Last Modified: 20 Apr 2025

    scripts/inspect_webbrowser.py in Reddit Terminal Viewer (RTV) 1.19.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17517

    Last Modified: 20 Apr 2025

    libsylph/utils.c in Sylpheed through 3.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17511

    Last Modified: 20 Apr 2025

    KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to prefs.c and worldgui.c.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17514

    Last Modified: 20 Apr 2025

    boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17515

    Last Modified: 20 Apr 2025

    etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the code to access this environment variable is not enabled in the shipped product

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17519

    Last Modified: 20 Apr 2025

    batteriesConfig.mlp in OCaml Batteries Included (aka ocaml-batteries) 2.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17524

    Last Modified: 20 Apr 2025

    library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17525

    Last Modified: 20 Apr 2025

    guiclient/guiclient.cpp in xTuple PostBooks 4.7.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17526

    Last Modified: 20 Apr 2025

    Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17527

    Last Modified: 20 Apr 2025

    delphi_gui/WWWBrowserRunnerDM.pas in PasDoc 0.14 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer has indicated that the code referencing the BROWSER environment variable is never used

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17528

    Last Modified: 20 Apr 2025

    backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17530

    Last Modified: 20 Apr 2025

    common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: this is disputed by a third party because no untrusted input can be used for the injection

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17532

    Last Modified: 20 Apr 2025

    examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17534

    Last Modified: 20 Apr 2025

    uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17521.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17518

    Last Modified: 20 Apr 2025

    swt/motif/browser.c in White_dune (aka whitedune) 0.30.10 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: This issue is being disputed as not being a vulnerability because β€œthe current version of white_dune (1.369 at https://wdune.ourproject.org/) do not use a "BROWSER environment variable". Instead, the "browser" variable is read from the $HOME/.dunerc file (or from the M$Windows registry). It is configurable in the "options" menu. The default is chosen in the ./configure script, which tests various programs, first tested is "xdg-open".

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17520

    Last Modified: 20 Apr 2025

    tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has reported that this is intentional behavior, because the documentation states "url_handler.pl was designed to work together with tin which only issues shell escaped absolute URLs.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17529

    Last Modified: 20 Apr 2025

    af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    8.8
    High

    CVE-2017-17531

    Last Modified: 20 Apr 2025

    gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

    Published: 14 Dec 2017
    Items Per Page