CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-1000410

    Last Modified: 20 Apr 2025

    The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these configuration messages, an attacker can also gain some control over which data will be held in the uninitialized stack variables. This can allow him to bypass KASLR, and stack canaries protection - as both pointers and stack canaries may be leaked in this manner. Combining this vulnerability (for example) with the previously disclosed RCE vulnerability in L2CAP configuration parsing (CVE-2017-1000251) may allow an attacker to exploit the RCE against kernels which were built with the above mitigations. These are the specifics of this vulnerability: In the function l2cap_parse_conf_rsp and in the function l2cap_parse_conf_req the following variable is declared without initialization: struct l2cap_conf_efs efs; In addition, when parsing input configuration parameters in both of these functions, the switch case for handling EFS elements may skip the memcpy call that will write to the efs variable: ... case L2CAP_CONF_EFS: if (olen == sizeof(efs)) memcpy(&efs, (void *)val, olen); ... The olen in the above if is attacker controlled, and regardless of that if, in both of these functions the efs variable would eventually be added to the outgoing configuration request that is being built: l2cap_add_conf_opt(&ptr, L2CAP_CONF_EFS, sizeof(efs), (unsigned long) &efs); So by sending a configuration request, or response, that contains an L2CAP_CONF_EFS element, but with an element length that is not sizeof(efs) - the memcpy to the uninitialized efs variable can be avoided, and the uninitialized variable would be returned to the attacker (16 bytes).

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15419

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by triggering a leaked cross-origin URL via a crafted HTML page.

    Published: 6 Dec 2017
    6.1
    Medium

    CVE-2017-15427

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

    Published: 6 Dec 2017
    6.1
    Medium

    CVE-2017-11481

    Last Modified: 20 Apr 2025

    Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

    Published: 6 Dec 2017
    9.8
    Critical

    CVE-2017-14374

    Last Modified: 20 Apr 2025

    The SMI-S service in Dell Storage Manager versions earlier than 16.3.20 (aka 2016 R3.20) is protected using a hard-coded password. A remote user with the knowledge of the password might potentially disable the SMI-S service via HTTP requests, affecting storage management and monitoring functionality via the SMI-S interface. This issue, aka DSM-30415, only affects a Windows installation of the Data Collector (not applicable to the virtual appliance).

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15413

    Last Modified: 21 Nov 2024

    Type confusion in WebAssembly in V8 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15420

    Last Modified: 21 Nov 2024

    Incorrect handling of back navigations in error pages in Navigation in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15422

    Last Modified: 21 Nov 2024

    Integer overflow in international date handling in International Components for Unicode (ICU) for C/C++ before 60.1, as used in V8 in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15409

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15410

    Last Modified: 21 Nov 2024

    Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15411

    Last Modified: 21 Nov 2024

    Use after free in PDFium in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15415

    Last Modified: 21 Nov 2024

    Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML page.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15416

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Blob API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page, aka a Blink out-of-bounds read.

    Published: 6 Dec 2017
    5.3
    Medium

    CVE-2017-15417

    Last Modified: 21 Nov 2024

    Inappropriate implementation in Skia canvas composite operations in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 6 Dec 2017
    4.3
    Medium

    CVE-2017-15418

    Last Modified: 21 Nov 2024

    Use of uninitialized memory in Skia in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15424

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15425

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 6 Dec 2017
    6.5
    Medium

    CVE-2017-15426

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 6 Dec 2017
    7.5
    High

    CVE-2017-12169

    Last Modified: 21 Nov 2024

    It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authenticated attacker could potentially use this flaw to disclose the password hashes belonging to Stage Users. This security issue does not result in disclosure of password hashes belonging to active standard users. NOTE: some developers feel that this report is a suggestion for a design change to Stage User activation, not a statement of a vulnerability.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15407

    Last Modified: 21 Nov 2024

    Out-of-bounds Write in the QUIC networking stack in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to gain code execution via a malicious server.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15408

    Last Modified: 21 Nov 2024

    Heap buffer overflow in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file that is mishandled by PDFium.

    Published: 6 Dec 2017
    8.8
    High

    CVE-2017-15412

    Last Modified: 21 Nov 2024

    Use after free in libxml2 before 2.9.5, as used in Google Chrome prior to 63.0.3239.84 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Dec 2017
    5.3
    Medium

    CVE-2017-15423

    Last Modified: 21 Nov 2024

    Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA512(password) by inspecting protocol traffic.

    Published: 6 Dec 2017
    7.5
    High

    CVE-2017-17432

    Last Modified: 20 Apr 2025

    OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underflow and assertion failure for a small MTU value.

    Published: 6 Dec 2017
    4.8
    Medium

    CVE-2017-14018

    Last Modified: 20 Apr 2025

    An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-14355

    Last Modified: 20 Apr 2025

    A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to allow escalation of privilege.

    Published: 5 Dec 2017
    6.1
    Medium

    CVE-2017-17431

    Last Modified: 20 Apr 2025

    GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.

    Published: 5 Dec 2017
    5.9
    Medium

    CVE-2017-4920

    Last Modified: 20 Apr 2025

    The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may exploit this issue resulting in continuous sending of LSAs between two routers eventually going in loop or loss of connectivity.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-14895

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, after a subsystem reset, iwpriv is not giving correct information.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14908

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does not properly validate the number of blocks to verify.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-11006

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during positioning.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-11007

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of stack corruption due to buffer overflow of Partition name while converting ascii string to unicode string in function HandleMetaImgFlash.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-11043

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a WiFI driver function, an integer overflow leading to heap buffer overflow may potentially occur.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-14897

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while handling the QSEOS_RPMB_CHECK_PROV_STATUS_COMMAND, a userspace buffer is directly accessed in kernel space.

    Published: 5 Dec 2017
    7
    High

    CVE-2017-14902

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, due to a race condition in the GLink kernel driver, a Use After Free condition can potentially occur.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-14904

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a crafted binder request can cause an arbitrary unmap in MediaServer.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14909

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a count value that is read from a file is not properly validated.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14914

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, handles in the global client structure can become stale.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14916

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer sizes in the message passing interface are not properly validated.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14917

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, buffer sizes in the message passing interface are not properly validated.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14918

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the GPS location wireless interface, a Use After Free condition can occur.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-6211

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the processing of a downlink supplementary services message, a buffer overflow can occur.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-9716

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qbt1000 driver implements an alternative channel for usermode applications to talk to QSEE applications.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-11005

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during a deinitialization path.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-11019

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the fd allocated during the get_metadata was not closed even though the buffer allocated to the fd was freed. This resulted in a failure during exit sequence.

    Published: 5 Dec 2017
    7.5
    High

    CVE-2017-11031

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl command can be used to cause a Use After Free condition.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-11033

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the coresight-tmc driver, a simultaneous read and enable of the ETR device after changing the buffer size may result in a Use After Free condition of the previous buffer.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-11047

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a graphics driver ioctl handler, the lack of copy_from_user() function calls may result in writes to kernel memory.

    Published: 5 Dec 2017
    9.8
    Critical

    CVE-2017-14907

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, cryptographic strength is reduced while deriving disk encryption key.

    Published: 5 Dec 2017
    7.8
    High

    CVE-2017-14896

    Last Modified: 20 Apr 2025

    In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a memory allocation without a length field validation in the mobicore driver which can result in an undersize buffer allocation. Ultimately this can result in a kernel memory overwrite.

    Published: 5 Dec 2017