CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-17130

    Last Modified: 20 Apr 2025

    The ff_free_picture_tables function in libavcodec/mpegpicture.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to vc1_decode_i_blocks_adv.

    Published: 4 Dec 2017
    5.5
    Medium

    CVE-2017-17113

    Last Modified: 20 Apr 2025

    ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 has a NULL pointer dereference via a 0x830000c4 DeviceIoControl request.

    Published: 4 Dec 2017
    6.5
    Medium

    CVE-2017-17127

    Last Modified: 20 Apr 2025

    The vc1_decode_frame function in libavcodec/vc1dec.c in Libav 12.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

    Published: 4 Dec 2017
    3.7
    Low

    CVE-2017-17433

    Last Modified: 20 Apr 2025

    The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote attackers to bypass intended access restrictions.

    Published: 4 Dec 2017
    9.8
    Critical

    CVE-2017-17434

    Last Modified: 20 Apr 2025

    The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechanism to pathnames found in "xname follows" strings (in the read_ndx_and_attrs function in rsync.c), which allows remote attackers to bypass intended access restrictions.

    Published: 4 Dec 2017
    7.5
    High

    CVE-2017-8315

    Last Modified: 21 Nov 2024

    Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

    Published: 4 Dec 2017
    7.5
    High

    CVE-2017-7843

    Last Modified: 25 Nov 2025

    When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and Firefox < 57.0.1.

    Published: 4 Dec 2017
    7.8
    High

    CVE-2017-17099

    Last Modified: 20 Apr 2025

    There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.

    Published: 3 Dec 2017
    6.1
    Medium

    CVE-2017-17096

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Content Cards plugin before 0.9.7 for WordPress allows remote attackers to inject arbitrary JavaScript via crafted OpenGraph data.

    Published: 3 Dec 2017
    6.1
    Medium

    CVE-2017-14516

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in SAP Business Objects Financial Consolidation before 2017-06-13, aka SAP Security Note 2422292.

    Published: 3 Dec 2017
    Unknown

    CVE-2017-17082

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Dec 2017
    8.1
    High

    CVE-2017-8823

    Last Modified: 20 Apr 2025

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka TROVE-2017-013.

    Published: 3 Dec 2017
    7.5
    High

    CVE-2017-8819

    Last Modified: 20 Apr 2025

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.

    Published: 3 Dec 2017
    7.5
    High

    CVE-2017-8820

    Last Modified: 20 Apr 2025

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory authorities via a malformed descriptor, aka TROVE-2017-010.

    Published: 3 Dec 2017
    7.5
    High

    CVE-2017-8821

    Last Modified: 20 Apr 2025

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requiring a password, which triggers an attempt by the OpenSSL library to ask the user for the password, aka TROVE-2017-011.

    Published: 3 Dec 2017
    3.7
    Low

    CVE-2017-8822

    Last Modified: 20 Apr 2025

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

    Published: 3 Dec 2017
    9.8
    Critical

    CVE-2022-23219

    Last Modified: 5 May 2025

    The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

    Published: 3 Dec 2017
    7.8
    High

    CVE-2017-17448

    Last Modified: 20 Apr 2025

    net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for new, get, and del operations, which allows local users to bypass intended access restrictions because the nfnl_cthelper_list data structure is shared across all net namespaces.

    Published: 3 Dec 2017
    5.4
    Medium

    CVE-2017-17093

    Last Modified: 20 Apr 2025

    wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

    Published: 2 Dec 2017
    5.4
    Medium

    CVE-2017-17094

    Last Modified: 20 Apr 2025

    wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

    Published: 2 Dec 2017
    8.8
    High

    CVE-2017-17091

    Last Modified: 20 Apr 2025

    wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

    Published: 2 Dec 2017
    5.4
    Medium

    CVE-2017-17092

    Last Modified: 20 Apr 2025

    wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

    Published: 2 Dec 2017
    7.5
    High

    CVE-2017-17090

    Last Modified: 20 Apr 2025

    An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

    Published: 2 Dec 2017
    7.8
    High

    CVE-2018-5848

    Last Modified: 21 Nov 2024

    In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

    Published: 2 Dec 2017
    6.5
    Medium

    CVE-2017-14953

    Last Modified: 20 Apr 2025

    HikVision Wi-Fi IP cameras, when used in a wired configuration, allow physically proximate attackers to trigger association with an arbitrary access point by leveraging a default SSID with no WiFi encryption or authentication. NOTE: Vendor states that this is not a vulnerability, but more an increase to the attack surface of the product

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-13663

    Last Modified: 20 Apr 2025

    Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-13664

    Last Modified: 20 Apr 2025

    Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrative privileges by retrieving credentials from this file.

    Published: 1 Dec 2017
    9.1
    Critical

    CVE-2017-14487

    Last Modified: 20 Apr 2025

    The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token fields in data/data/com.ohmibod.remote2/shared_prefs/OMB.xml.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-14486

    Last Modified: 20 Apr 2025

    The Vibease Wireless Remote Vibrator app for Android and the Vibease Chat app for iOS use cleartext to exchange messages with other apps and the PLAIN SASL mechanism to send auth tokens to Vibease servers, which allows remote attackers to obtain user credentials, messages, and other sensitive information by sniffing the network for XMPP traffic.

    Published: 1 Dec 2017
    7.4
    High

    CVE-2017-15357

    Last Modified: 20 Apr 2025

    The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

    Published: 1 Dec 2017
    7.8
    High

    CVE-2017-16895

    Last Modified: 20 Apr 2025

    The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-16953

    Last Modified: 20 Apr 2025

    connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.

    Published: 1 Dec 2017
    6.5
    Medium

    CVE-2017-16893

    Last Modified: 20 Apr 2025

    The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. tags.php is affected: values of the edit_list parameters are not sanitized; these are used to construct an SQL query and retrieve a list of registered users into the application.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-15701

    Last Modified: 20 Apr 2025

    In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory and eventually terminate. Older AMQP protocols are not affected.

    Published: 1 Dec 2017
    9.1
    Critical

    CVE-2017-10861

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command.

    Published: 1 Dec 2017
    7.8
    High

    CVE-2017-10892

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-10900

    Last Modified: 20 Apr 2025

    PTW-WMS1 firmware version 2.000.012 allows remote attackers to bypass access restrictions to obtain or delete data on the disk via unspecified vectors.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-10874

    Last Modified: 20 Apr 2025

    PWR-Q200 does not use random values for source ports of DNS query packets, which allows remote attackers to conduct DNS cache poisoning attacks.

    Published: 1 Dec 2017
    7.8
    High

    CVE-2017-10891

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Media Go version 3.2.0.191 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-10894

    Last Modified: 20 Apr 2025

    StreamRelay.NET.exe ver2.14.0.7 and earlier allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-10895

    Last Modified: 20 Apr 2025

    sDNSProxy.exe ver1.1.0.0 and earlier allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-10898

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-10899

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-10902

    Last Modified: 20 Apr 2025

    PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-10903

    Last Modified: 20 Apr 2025

    Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-10901

    Last Modified: 20 Apr 2025

    Buffer overflow in PTW-WMS1 firmware version 2.000.012 allows remote attackers to conduct denial-of-service attacks via unspecified vectors.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-11284

    Last Modified: 20 Apr 2025

    Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

    Published: 1 Dec 2017
    6.1
    Medium

    CVE-2017-3104

    Last Modified: 20 Apr 2025

    Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.

    Published: 1 Dec 2017
    9.8
    Critical

    CVE-2017-11283

    Last Modified: 20 Apr 2025

    Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

    Published: 1 Dec 2017
    7.5
    High

    CVE-2017-11286

    Last Modified: 20 Apr 2025

    Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

    Published: 1 Dec 2017