CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-17474

    Last Modified: 20 Apr 2025

    TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730070.

    Published: 8 Dec 2017
    7.8
    High

    CVE-2017-17475

    Last Modified: 20 Apr 2025

    TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82736068.

    Published: 8 Dec 2017
    7.5
    High

    CVE-2017-17463

    Last Modified: 20 Apr 2025

    Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.

    Published: 8 Dec 2017
    9.8
    Critical

    CVE-2017-17464

    Last Modified: 20 Apr 2025

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.

    Published: 8 Dec 2017
    9.8
    Critical

    CVE-2017-17465

    Last Modified: 20 Apr 2025

    K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.

    Published: 8 Dec 2017
    Unknown

    CVE-2017-17461

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Dec 2017
    8.8
    High

    CVE-2017-17509

    Last Modified: 20 Apr 2025

    In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

    Published: 8 Dec 2017
    6.5
    Medium

    CVE-2017-17505

    Last Modified: 20 Apr 2025

    In HDF5 1.10.1, there is a NULL pointer dereference in the function H5O_pline_decode in the H5Opline.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

    Published: 8 Dec 2017
    6.5
    Medium

    CVE-2017-17507

    Last Modified: 20 Apr 2025

    In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5T_conv_struct_opt in H5Tconv.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

    Published: 8 Dec 2017
    5.5
    Medium

    CVE-2017-15127

    Last Modified: 21 Nov 2024

    A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local denial of service (BUG).

    Published: 8 Dec 2017
    5.5
    Medium

    CVE-2017-15128

    Last Modified: 21 Nov 2024

    A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).

    Published: 8 Dec 2017
    8.8
    High

    CVE-2017-16909

    Last Modified: 21 Nov 2024

    An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.

    Published: 8 Dec 2017
    6.5
    Medium

    CVE-2017-16910

    Last Modified: 21 Nov 2024

    An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.

    Published: 8 Dec 2017
    9.8
    Critical

    CVE-2017-17479

    Last Modified: 20 Apr 2025

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtoimage function in jpwl/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

    Published: 8 Dec 2017
    9.8
    Critical

    CVE-2017-17480

    Last Modified: 20 Apr 2025

    In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

    Published: 8 Dec 2017
    6.5
    Medium

    CVE-2017-17506

    Last Modified: 20 Apr 2025

    In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

    Published: 8 Dec 2017
    6.5
    Medium

    CVE-2017-17508

    Last Modified: 20 Apr 2025

    In HDF5 1.10.1, there is a divide-by-zero vulnerability in the function H5T_set_loc in the H5T.c file in libhdf5.a. For example, h5dump would crash when someone opens a crafted hdf5 file.

    Published: 8 Dec 2017
    5.5
    Medium

    CVE-2017-18232

    Last Modified: 21 Nov 2024

    The Serial Attached SCSI (SAS) implementation in the Linux kernel through 4.15.9 mishandles a mutex within libsas, which allows local users to cause a denial of service (deadlock) by triggering certain error-handling code.

    Published: 8 Dec 2017
    3.3
    Low

    CVE-2017-17807

    Last Modified: 20 Apr 2025

    The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing a local user to use a sequence of crafted system calls to add keys to a keyring with only Search permission (not Write permission) to that keyring, related to construct_get_dest_keyring() in security/keys/request_key.c.

    Published: 8 Dec 2017
    6.1
    Medium

    CVE-2017-14386

    Last Modified: 20 Apr 2025

    The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.

    Published: 7 Dec 2017
    8.8
    High

    CVE-2017-17459

    Last Modified: 20 Apr 2025

    http_transport.c in Fossil before 2.4, when the SSH sync protocol is used, allows user-assisted remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-14176, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.

    Published: 7 Dec 2017
    7.8
    High

    CVE-2017-11937

    Last Modified: 20 Apr 2025

    The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to remote code execution. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability".

    Published: 7 Dec 2017
    7.5
    High

    CVE-2017-1271

    Last Modified: 20 Apr 2025

    IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 124746.

    Published: 7 Dec 2017
    8.8
    High

    CVE-2017-1356

    Last Modified: 20 Apr 2025

    IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 126683.

    Published: 7 Dec 2017
    6.5
    Medium

    CVE-2017-1433

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 7.5, 8.0, and 9.0 could allow an authenticated user to insert messages with a corrupt RFH header into the channel which would cause it to restart. IBM X-Force ID: 127803.

    Published: 7 Dec 2017
    4.3
    Medium

    CVE-2017-1481

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.

    Published: 7 Dec 2017
    3.7
    Low

    CVE-2017-1497

    Last Modified: 20 Apr 2025

    IBM Sterling File Gateway 2.2 could allow an unauthorized user to view files they should not have access to providing they know the directory location of the file. IBM X-Force ID: 128695.

    Published: 7 Dec 2017
    4.4
    Medium

    CVE-2017-1336

    Last Modified: 20 Apr 2025

    IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.

    Published: 7 Dec 2017
    3.7
    Low

    CVE-2017-1341

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 and 9.0 could allow, under special circumstances, an unauthorized user to access an object which they should have been denied access. IBM X-Force ID: 126456.

    Published: 7 Dec 2017
    4.3
    Medium

    CVE-2017-1342

    Last Modified: 20 Apr 2025

    IBM Insights Foundation for Energy 2.0 could reveal sensitive information in error messages to authenticated users that could e used to conduct further attacks. IBM X-Force ID: 126457.

    Published: 7 Dec 2017
    3.5
    Low

    CVE-2017-1353

    Last Modified: 20 Apr 2025

    IBM Atlas eDiscovery Process Management 6.0.3 could allow an authenticated attacker to obtain sensitive information when an unsuspecting user clicks on unsafe third-party links. IBM X-Force ID: 126680.

    Published: 7 Dec 2017
    5.4
    Medium

    CVE-2017-1354

    Last Modified: 20 Apr 2025

    IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126681.

    Published: 7 Dec 2017
    3.7
    Low

    CVE-2017-1355

    Last Modified: 20 Apr 2025

    IBM Atlas eDiscovery Process Management 6.0.3 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 126682.

    Published: 7 Dec 2017
    6.5
    Medium

    CVE-2017-1487

    Last Modified: 20 Apr 2025

    IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: 128626.

    Published: 7 Dec 2017
    5.4
    Medium

    CVE-2017-1498

    Last Modified: 20 Apr 2025

    IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 129020.

    Published: 7 Dec 2017
    5.4
    Medium

    CVE-2017-1465

    Last Modified: 20 Apr 2025

    IBM TRIRIGA 3.2, 3.3, 3.4, and 3.5 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 128464.

    Published: 7 Dec 2017
    5.4
    Medium

    CVE-2017-1482

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128620.

    Published: 7 Dec 2017
    9.8
    Critical

    CVE-2017-17430

    Last Modified: 20 Apr 2025

    Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.

    Published: 7 Dec 2017
    8.8
    High

    CVE-2017-17384

    Last Modified: 20 Apr 2025

    ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.

    Published: 7 Dec 2017
    5.9
    Medium

    CVE-2017-16913

    Last Modified: 21 Nov 2024

    The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial of service (arbitrary memory allocation) via a specially crafted USB over IP packet.

    Published: 7 Dec 2017
    5.9
    Medium

    CVE-2017-16914

    Last Modified: 21 Nov 2024

    The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer dereference) via a specially crafted USB over IP packet.

    Published: 7 Dec 2017
    8.8
    High

    CVE-2017-17436

    Last Modified: 20 Apr 2025

    An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session between the Android application and the safe. The website and marketing materials advertise that this communication channel is encrypted with "Highest Level Bluetooth Encryption" and "Data transmissions are secure via AES256 bit encryption." These claims, however, are not true. Moreover, AES256 bit encryption is not supported in the Bluetooth Low Energy (BLE) standard, so it would have to be at the application level. This lack of encryption allows an individual to learn the passcode by eavesdropping on the communications between the application and the safe.

    Published: 7 Dec 2017
    3.3
    Low

    CVE-2017-17456

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14245. Reason: This candidate is a duplicate of CVE-2017-14245. Notes: All CVE users should reference CVE-2017-14245 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Dec 2017
    3.3
    Low

    CVE-2017-17457

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14246. Reason: This candidate is a duplicate of CVE-2017-14246. Notes: All CVE users should reference CVE-2017-14246 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Dec 2017
    6.5
    Medium

    CVE-2017-15097

    Last Modified: 21 Nov 2024

    Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

    Published: 7 Dec 2017
    9.1
    Critical

    CVE-2017-15896

    Last Modified: 20 Apr 2025

    Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

    Published: 7 Dec 2017
    3.1
    Low

    CVE-2017-15897

    Last Modified: 20 Apr 2025

    Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

    Published: 7 Dec 2017
    8.8
    High

    CVE-2017-17435

    Last Modified: 20 Apr 2025

    An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlock any safe in this product line without a valid PIN code. Even though the phone application requires it and there is a field to supply the PIN code in an authorization request, the safe does not check the PIN code, so an attacker can obtain authorization using any value. Once an attacker sees the Bluetooth Low Energy (BLE) advertisement for the safe, they need only to write a BLE characteristic to enable notifications, and send a crafted getAuthor packet that returns a temporary key, and an unlock packet including that temporary key. The safe then opens after the unlock packet is processed, with no verification of PIN or other credentials.

    Published: 7 Dec 2017
    6.1
    Medium

    CVE-2017-17451

    Last Modified: 20 Apr 2025

    The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subscription/unsubscribe2.php.

    Published: 7 Dec 2017
    7.5
    High

    CVE-2017-3144

    Last Modified: 21 Nov 2024

    A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects ISC DHCP 4.1.0 to 4.1-ESV-R15, 4.2.0 to 4.2.8, 4.3.0 to 4.3.6. Older versions may also be affected but are well beyond their end-of-life (EOL). Releases prior to 4.1.0 have not been tested.

    Published: 7 Dec 2017