CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-5706

    Last Modified: 20 Apr 2025

    Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.

    Published: 21 Nov 2017
    7.8
    High

    CVE-2017-5707

    Last Modified: 20 Apr 2025

    Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

    Published: 21 Nov 2017
    7.8
    High

    CVE-2017-5708

    Last Modified: 20 Apr 2025

    Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecified vector.

    Published: 21 Nov 2017
    7.2
    High

    CVE-2017-5712

    Last Modified: 20 Apr 2025

    Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.

    Published: 21 Nov 2017
    7.8
    High

    CVE-2017-5711

    Last Modified: 20 Apr 2025

    Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.

    Published: 21 Nov 2017
    7.4
    High

    CVE-2017-5729

    Last Modified: 20 Apr 2025

    Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.

    Published: 21 Nov 2017
    8.8
    High

    CVE-2017-15044

    Last Modified: 20 Apr 2025

    The default installation of DocuWare Fulltext Search server through 6.11 allows remote users to connect to and download searchable text from the embedded Solr service, bypassing DocuWare's access control features of the DocuWare user interfaces and API. An attacker can also gain privileges by modifying text. The default installation is unsafe because the server listens on the network interface, not the localhost interface.

    Published: 21 Nov 2017
    9.8
    Critical

    CVE-2017-16613

    Last Modified: 20 Apr 2025

    An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechanism to a log file as part of a GET URI. This allows attackers to bypass authentication by inserting a token into an X-Auth-Token header of a new request. NOTE: github.com/openstack/swauth URLs do not mean that Swauth is maintained by an official OpenStack project team.

    Published: 21 Nov 2017
    9.8
    Critical

    CVE-2017-16920

    Last Modified: 20 Apr 2025

    v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via a member api swfupload action to index.php.

    Published: 21 Nov 2017
    9.8
    Critical

    CVE-2017-16840

    Last Modified: 20 Apr 2025

    The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.

    Published: 21 Nov 2017
    5.4
    Medium

    CVE-2017-16919

    Last Modified: 20 Apr 2025

    MapOS 3.1.11 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in /clientes/visualizar, which allows remote attackers to inject arbitrary web script or HTML via a crafted description parameter.

    Published: 21 Nov 2017
    7.5
    High

    CVE-2017-15275

    Last Modified: 20 Apr 2025

    Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.

    Published: 21 Nov 2017
    8.8
    High

    CVE-2017-11509

    Last Modified: 21 Nov 2024

    An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.

    Published: 21 Nov 2017
    6.5
    Medium

    CVE-2017-17504

    Last Modified: 20 Apr 2025

    ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.

    Published: 21 Nov 2017
    9.8
    Critical

    CVE-2017-14746

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

    Published: 21 Nov 2017
    9.8
    Critical

    CVE-2017-17484

    Last Modified: 20 Apr 2025

    The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC.

    Published: 21 Nov 2017
    5.9
    Medium

    CVE-2018-1298

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthenticated attacker to crash the broker instance. AMQP 1.0 and HTTP connections are not affected. An authentication of incoming AMQP connections in Apache Qpid Broker-J is performed by special entities called "Authentication Providers". Each Authentication Provider can support several SASL mechanisms which are offered to the connecting clients as part of SASL negotiation process. The client chooses the most appropriate SASL mechanism for authentication. Authentication Providers of following types supports PLAIN SASL mechanism: Plain, PlainPasswordFile, SimpleLDAP, Base64MD5PasswordFile, MD5, SCRAM-SHA-256, SCRAM-SHA-1. XOAUTH2 SASL mechanism is supported by Authentication Providers of type OAuth2. If an AMQP port is configured with any of these Authentication Providers, the Broker may be vulnerable.

    Published: 21 Nov 2017
    8.8
    High

    CVE-2017-12110

    Last Modified: 20 Apr 2025

    An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corruption resulting in remote code execution.

    Published: 20 Nov 2017
    8.8
    High

    CVE-2017-12111

    Last Modified: 20 Apr 2025

    An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4. A specially crafted XLS file with a formula record can cause memory corruption resulting in remote code execution. An attacker can send a malicious XLS file to trigger this vulnerability.

    Published: 20 Nov 2017
    7.8
    High

    CVE-2017-2896

    Last Modified: 20 Apr 2025

    An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

    Published: 20 Nov 2017
    7.8
    High

    CVE-2017-2897

    Last Modified: 20 Apr 2025

    An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.

    Published: 20 Nov 2017
    7.8
    High

    CVE-2017-2919

    Last Modified: 20 Apr 2025

    An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability

    Published: 20 Nov 2017
    5.4
    Medium

    CVE-2017-16907

    Last Modified: 20 Apr 2025

    In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.

    Published: 20 Nov 2017
    5.4
    Medium

    CVE-2017-16906

    Last Modified: 20 Apr 2025

    In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.

    Published: 20 Nov 2017
    5.4
    Medium

    CVE-2017-16908

    Last Modified: 20 Apr 2025

    In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the CVE-2015-7984 CSRF protection mechanism can then be bypassed.

    Published: 20 Nov 2017
    6.8
    Medium

    CVE-2017-15527

    Last Modified: 20 Apr 2025

    Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.

    Published: 20 Nov 2017
    6.1
    Medium

    CVE-2017-16904

    Last Modified: 20 Apr 2025

    The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.

    Published: 20 Nov 2017
    9.8
    Critical

    CVE-2017-16903

    Last Modified: 20 Apr 2025

    LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, within a template Style add request to index.php.

    Published: 20 Nov 2017
    7.5
    High

    CVE-2017-16902

    Last Modified: 20 Apr 2025

    On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.

    Published: 20 Nov 2017
    5.5
    Medium

    CVE-2017-16898

    Last Modified: 20 Apr 2025

    The printMP3Headers function in util/listmp3.c in libming v0.4.8 or earlier is vulnerable to a global buffer overflow, which may allow attackers to cause a denial of service via a crafted file, a different vulnerability than CVE-2016-9264.

    Published: 20 Nov 2017
    9.8
    Critical

    CVE-2017-16896

    Last Modified: 20 Apr 2025

    A SQL injection in classes/handler/public.php in the forgotpass component of Tiny Tiny RSS 17.4 exists via the login parameter.

    Published: 20 Nov 2017
    7.8
    High

    CVE-2016-6804

    Last Modified: 20 Apr 2025

    The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the location in which the installer is run has been previously poisoned by a file that impersonates a dynamic-link library that the installer depends upon.

    Published: 20 Nov 2017
    6.8
    Medium

    CVE-2017-11400

    Last Modified: 20 Apr 2025

    An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. An incomplete firmware signature allows a local attacker to upgrade the equipment (kernel, file system) with unsigned, attacker-controlled, data. This occurs because the appliance_config file is signed but the .tar.sec file is unsigned.

    Published: 20 Nov 2017
    9.8
    Critical

    CVE-2017-11401

    Last Modified: 20 Apr 2025

    An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.

    Published: 20 Nov 2017
    9.8
    Critical

    CVE-2017-11402

    Last Modified: 20 Apr 2025

    An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Design flaws in OPC classic and in custom netfilter modules allow an attacker to remotely activate rules on the firewall and to connect to any TCP port of a protected asset, thus bypassing the firewall. The attack methodology is a crafted OPC dynamic port shift.

    Published: 20 Nov 2017
    4.3
    Medium

    CVE-2017-15110

    Last Modified: 20 Apr 2025

    In Moodle 3.x, students can find out email addresses of other students in the same course. Using search on the Participants page, students could search email addresses of all participants regardless of email visibility. This allows enumerating and guessing emails of other students.

    Published: 20 Nov 2017
    7.5
    High

    CVE-2017-16894

    Last Modified: 20 Apr 2025

    In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

    Published: 20 Nov 2017
    7.1
    High

    CVE-2017-16899

    Last Modified: 20 Apr 2025

    An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the read_textobject functions in read.c and read1_3.c.

    Published: 20 Nov 2017
    7.5
    High

    CVE-2017-16892

    Last Modified: 20 Apr 2025

    In Bftpd before 4.7, there is a memory leak in the file rename function.

    Published: 19 Nov 2017
    6.5
    Medium

    CVE-2017-17760

    Last Modified: 20 Apr 2025

    OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.

    Published: 19 Nov 2017
    5.5
    Medium

    CVE-2017-17975

    Last Modified: 20 Apr 2025

    Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 allows attackers to cause a denial of service (system crash) or possibly have unspecified other impact by triggering failure of audio registration, because a kfree of the usbtv data structure occurs during a usbtv_video_free call, but the usbtv_video_fail label's code attempts to both access and free this data structure.

    Published: 19 Nov 2017
    6.5
    Medium

    CVE-2017-16883

    Last Modified: 20 Apr 2025

    The outputSWF_TEXT_RECORD function in util/outputscript.c in libming <= 0.4.8 is vulnerable to a NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted swf file.

    Published: 18 Nov 2017
    7.8
    High

    CVE-2017-16882

    Last Modified: 20 Apr 2025

    Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin/log2ido.

    Published: 18 Nov 2017
    6.1
    Medium

    CVE-2017-16881

    Last Modified: 20 Apr 2025

    b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, processor/ArticleProcessor.java, processor/UserProcessor.java, service/ArticleQueryService.java, service/AvatarQueryService.java, and service/CommentQueryService.java.

    Published: 18 Nov 2017
    6.1
    Medium

    CVE-2017-14077

    Last Modified: 20 Apr 2025

    HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.

    Published: 18 Nov 2017
    5.5
    Medium

    CVE-2017-18005

    Last Modified: 20 Apr 2025

    Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.

    Published: 18 Nov 2017
    8.8
    High

    CVE-2017-18266

    Last Modified: 21 Nov 2024

    The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.

    Published: 18 Nov 2017
    7.8
    High

    CVE-2017-16879

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted terminfo file, as demonstrated by tic.

    Published: 18 Nov 2017
    9.8
    Critical

    CVE-2017-16566

    Last Modified: 20 Apr 2025

    On Jooan IP Camera A5 2.3.36 devices, an insecure FTP server does not require authentication, which allows remote attackers to read or replace core system files including those used for authentication (such as passwd and shadow). This can be abused to take full root level control of the device.

    Published: 17 Nov 2017
    8.8
    High

    CVE-2017-1000217

    Last Modified: 20 Apr 2025

    Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0.

    Published: 17 Nov 2017