CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2017-8866

    Last Modified: 20 Apr 2025

    Elemental Path's CogniToys Dino smart toys through firmware version 0.0.794 share a fixed small pool of hardcoded keys, allowing a remote attacker to use a different Dino device to decrypt VoIP traffic between a child's Dino and remote server.

    Published: 11 Dec 2017
    5.4
    Medium

    CVE-2017-1536

    Last Modified: 20 Apr 2025

    IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130733.

    Published: 11 Dec 2017
    5.4
    Medium

    CVE-2017-1549

    Last Modified: 20 Apr 2025

    IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131289.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17551

    Last Modified: 20 Apr 2025

    The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulnerability when attempting to restore browser settings from a malicious Dolphin Browser backup file. This arbitrary file write vulnerability allows an attacker to overwrite a specific executable in the Dolphin Browser's data directory with a crafted malicious executable. Every time the Dolphin Browser is launched, it will attempt to run the malicious executable from disk, thus executing the attacker's code.

    Published: 11 Dec 2017
    9.8
    Critical

    CVE-2017-15944

    Last Modified: 22 Apr 2026

    Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface.

    Published: 11 Dec 2017
    9.8
    Critical

    CVE-2017-17111

    Last Modified: 20 Apr 2025

    Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.

    Published: 11 Dec 2017
    6.5
    Medium

    CVE-2015-8470

    Last Modified: 20 Apr 2025

    The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-11319

    Last Modified: 20 Apr 2025

    Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.

    Published: 11 Dec 2017
    6.1
    Medium

    CVE-2015-6502

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the console in Puppet Enterprise before 2015.2.1 allows remote attackers to inject arbitrary web script or HTML via the string parameter, related to Login Redirect.

    Published: 11 Dec 2017
    6.7
    Medium

    CVE-2017-15870

    Last Modified: 20 Apr 2025

    Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking."

    Published: 11 Dec 2017
    9.8
    Critical

    CVE-2017-15940

    Last Modified: 20 Apr 2025

    The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 11 Dec 2017
    7.5
    High

    CVE-2017-15942

    Last Modified: 20 Apr 2025

    Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.13, and 8.0.x before 8.0.6 allows remote attackers to cause a denial of service via vectors related to the management interface.

    Published: 11 Dec 2017
    5.3
    Medium

    CVE-2017-15943

    Last Modified: 20 Apr 2025

    The configuration file import for applications, spyware and vulnerability objects functionality in the web interface in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, and 7.1.x before 7.1.14 allows remote attackers to conduct server-side request forgery (SSRF) attacks and consequently obtain sensitive information via vectors related to parsing of external entities.

    Published: 11 Dec 2017
    9.8
    Critical

    CVE-2017-17110

    Last Modified: 20 Apr 2025

    Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.

    Published: 11 Dec 2017
    7.8
    High

    CVE-2017-13070

    Last Modified: 20 Apr 2025

    A DLL Hijacking vulnerability in QNAP Qsync for Windows (exe) version 4.2.2.0724 and earlier could allow remote attackers to execute arbitrary code on Windows machines.

    Published: 11 Dec 2017
    6.1
    Medium

    CVE-2017-16723

    Last Modified: 20 Apr 2025

    A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (running firmware versions prior to 1.99, 2.20, or 2.40). The cross-site scripting vulnerability has been identified, which may allow remote code execution.

    Published: 11 Dec 2017
    8.1
    High

    CVE-2016-6904

    Last Modified: 20 Apr 2025

    Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.

    Published: 11 Dec 2017
    9.8
    Critical

    CVE-2017-15708

    Last Modified: 20 Apr 2025

    In Apache Synapse, by default no authentication is required for Java Remote Method Invocation (RMI). So Apache Synapse 3.0.1 or all previous releases (3.0.0, 2.1.0, 2.0.0, 1.2, 1.1.2, 1.1.1) allows remote code execution attacks that can be performed by injecting specially crafted serialized objects. And the presence of Apache Commons Collections 3.2.1 (commons-collections-3.2.1.jar) or previous versions in Synapse distribution makes this exploitable. To mitigate the issue, we need to limit RMI access to trusted users only. Further upgrading to 3.0.1 version will eliminate the risk of having said Commons Collection version. In Synapse 3.0.1, Commons Collection has been updated to 3.2.2 version.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17536

    Last Modified: 20 Apr 2025

    Phabricator before 2017-11-10 does not block the --config and --debugger flags to the Mercurial hg program, which allows remote attackers to execute arbitrary code by using the web UI to browse a branch whose name begins with a --config= or --debugger= substring.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-11463

    Last Modified: 20 Apr 2025

    In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17512

    Last Modified: 20 Apr 2025

    sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17523

    Last Modified: 20 Apr 2025

    lilypond-invoke-editor in LilyPond 2.19.80 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17502

    Last Modified: 20 Apr 2025

    ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17500

    Last Modified: 20 Apr 2025

    ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17503

    Last Modified: 20 Apr 2025

    ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

    Published: 11 Dec 2017
    4.8
    Medium

    CVE-2017-16789

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or HTML via the users management panel of the web interface.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17501

    Last Modified: 20 Apr 2025

    WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.

    Published: 11 Dec 2017
    8.8
    High

    CVE-2017-17498

    Last Modified: 20 Apr 2025

    WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 11 Dec 2017
    7.8
    High

    CVE-2017-1000408

    Last Modified: 21 Nov 2024

    A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

    Published: 11 Dec 2017
    6.5
    Medium

    CVE-2017-1000505

    Last Modified: 21 Nov 2024

    In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on the Jenkins master file system. Such a type coercion is now subject to sandbox protection and considered to be a call to the `new File(String)` constructor for the purpose of in-process script approval.

    Published: 11 Dec 2017
    Unknown

    CVE-2018-1359

    Last Modified: 6 May 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2018-1358

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17542

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17545

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17546

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17547

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17548

    Last Modified: 17 Mar 2025

    Not used

    Published: 11 Dec 2017
    6.6
    Medium

    CVE-2017-17558

    Last Modified: 20 Apr 2025

    The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write access) or possibly have unspecified other impact via a crafted USB device.

    Published: 11 Dec 2017
    6.5
    Medium

    CVE-2017-17741

    Last Modified: 20 Apr 2025

    The KVM implementation in the Linux kernel through 4.14.7 allows attackers to obtain potentially sensitive information from kernel memory, aka a write_mmio stack-based out-of-bounds read, related to arch/x86/kvm/x86.c and include/trace/events/kvm.h.

    Published: 11 Dec 2017
    7
    High

    CVE-2017-1000409

    Last Modified: 21 Nov 2024

    A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

    Published: 11 Dec 2017
    5.9
    Medium

    CVE-2017-16912

    Last Modified: 21 Nov 2024

    The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet.

    Published: 11 Dec 2017
    Unknown

    CVE-2017-17496

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Dec 2017
    7.5
    High

    CVE-2017-16241

    Last Modified: 20 Apr 2025

    Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, unlock, add ID card value) by sending unauthenticated requests to the affected devices via Serial over TCP/IP, as demonstrated by a Ud command.

    Published: 10 Dec 2017
    7
    High

    CVE-2017-17712

    Last Modified: 20 Apr 2025

    The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows a local user to execute code and gain privileges.

    Published: 10 Dec 2017
    6.5
    Medium

    CVE-2017-17722

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, there is a reachable assertion in the readHeader function in bigtiffimage.cpp, which will lead to a remote denial of service attack via a crafted TIFF file.

    Published: 10 Dec 2017
    8.1
    High

    CVE-2017-17723

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnerability to disclose memory data or cause a denial of service via a crafted TIFF file.

    Published: 10 Dec 2017
    6.5
    Medium

    CVE-2017-17724

    Last Modified: 21 Nov 2024

    In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, related to the "!= 0x1c" case. Remote attackers can exploit this vulnerability to cause a denial of service via a crafted TIFF file.

    Published: 10 Dec 2017
    8.8
    High

    CVE-2017-16362

    Last Modified: 20 Apr 2025

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability is an instance of an out of bounds read vulnerability in the MakeAccesible plugin, when handling font data. It causes an out of bounds memory access, which sometimes triggers an access violation exception. Attackers can exploit the vulnerability by using the out of bounds access for unintended reads, writes, or frees, potentially leading to code corruption, control-flow hijack, or an information leak attack.

    Published: 9 Dec 2017
    8.8
    High

    CVE-2017-16365

    Last Modified: 20 Apr 2025

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. The vulnerability is caused by a buffer over-read in the True Type2 Font parsing module. A corrupted cmap table input leads to a computation where the pointer arithmetic results in a location outside valid memory locations belonging to the buffer. An attack can be used to obtain sensitive information, such as object heap addresses, etc.

    Published: 9 Dec 2017
    8.8
    High

    CVE-2017-16370

    Last Modified: 20 Apr 2025

    An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. This vulnerability occurs because of a computation that reads data that is past the end of the target buffer; the computation is a part of the JavaScript engine. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

    Published: 9 Dec 2017