CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-1000221

    Last Modified: 20 Apr 2025

    In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have access to recordings published only for ROLE_USER_X.

    Published: 17 Nov 2017
    9.1
    Critical

    CVE-2017-1000190

    Last Modified: 12 Sept 2025

    SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-4939

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) installer contains a DLL hijacking issue that exists due to some DLL files loaded by the application improperly. This issue may allow an attacker to load a DLL file of the attacker's choosing that could execute arbitrary code.

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-1000163

    Last Modified: 20 Apr 2025

    The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000227

    Last Modified: 20 Apr 2025

    Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000230

    Last Modified: 20 Apr 2025

    The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulting in denial of service attack.

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-16880

    Last Modified: 20 Apr 2025

    The dump function in Util/TemplateHelper.php in filp whoops before 2.1.13 has XSS.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000215

    Last Modified: 20 Apr 2025

    ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution

    Published: 17 Nov 2017
    Unknown

    CVE-2017-1000204

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9920. Reason: This candidate is a reservation duplicate of CVE-2016-9920. Notes: All CVE users should reference CVE-2016-9920 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Nov 2017
    7.2
    High

    CVE-2017-14111

    Last Modified: 20 Apr 2025

    The workstation logging function in Philips IntelliSpace Cardiovascular (ISCV) 2.3.0 and earlier and Xcelera R4.1L1 and earlier records domain authentication credentials, which if accessed allows an attacker to use credentials to access the application, or other user entitlements.

    Published: 17 Nov 2017
    Unknown

    CVE-2017-1000161

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 17 Nov 2017
    7.4
    High

    CVE-2017-6168

    Last Modified: 20 Apr 2025

    On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (fixed in 13.0.0 HF3) a virtual server configured with a Client SSL profile may be vulnerable to an Adaptive Chosen Ciphertext attack (AKA Bleichenbacher attack) against RSA, which when exploited, may result in plaintext recovery of encrypted messages and/or a Man-in-the-middle (MiTM) attack, despite the attacker not having gained access to the server's private key itself, aka a ROBOT attack.

    Published: 17 Nov 2017
    6.5
    Medium

    CVE-2017-1000168

    Last Modified: 20 Apr 2025

    sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys

    Published: 17 Nov 2017
    4.8
    Medium

    CVE-2017-13700

    Last Modified: 20 Apr 2025

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. There is XSS in the administration interface.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000169

    Last Modified: 20 Apr 2025

    QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.

    Published: 17 Nov 2017
    Unknown

    CVE-2017-1000233

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11667. Reason: This candidate is a reservation duplicate of CVE-2017-11667. Notes: All CVE users should reference CVE-2017-11667 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-13703

    Last Modified: 20 Apr 2025

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. A denial of service may occur.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000170

    Last Modified: 20 Apr 2025

    jqueryFileTree 2.1.5 and older Directory Traversal

    Published: 17 Nov 2017
    Unknown

    CVE-2017-1000222

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 17 Nov 2017
    5.3
    Medium

    CVE-2017-13702

    Last Modified: 20 Apr 2025

    An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. Cookies can be stolen, manipulated, and reused.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000191

    Last Modified: 20 Apr 2025

    Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000192

    Last Modified: 20 Apr 2025

    Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login and password from the database, private encryption key, as well as other sensitive information.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-16819

    Last Modified: 20 Apr 2025

    A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-16877

    Last Modified: 20 Apr 2025

    ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-16875

    Last Modified: 20 Apr 2025

    An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unregistration will trigger an integer overflow, which may cause ioqueue backends to reject future key registrations.

    Published: 17 Nov 2017
    8.8
    High

    CVE-2017-1000203

    Last Modified: 20 Apr 2025

    ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000206

    Last Modified: 20 Apr 2025

    samtools htslib library version 1.4.0 and earlier is vulnerable to buffer overflow in the CRAM rANS codec resulting in potential arbitrary code execution

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000212

    Last Modified: 20 Apr 2025

    Elixir's vim plugin, alchemist.vim is vulnerable to remote code execution in the bundled alchemist-server. A malicious website can execute requests against an ephemeral port on localhost that are then evaluated as elixir code.

    Published: 17 Nov 2017
    5.3
    Medium

    CVE-2017-1000211

    Last Modified: 20 Apr 2025

    Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

    Published: 17 Nov 2017
    6.5
    Medium

    CVE-2017-4938

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a guest RPC NULL pointer dereference vulnerability. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-10887

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-10888

    Last Modified: 20 Apr 2025

    BOOK WALKER for Windows Ver.1.2.9 and earlier, BOOK WALKER for Mac Ver.1.2.5 and earlier allow an attacker to access local files via unspecified vectors.

    Published: 17 Nov 2017
    4.3
    Medium

    CVE-2017-10889

    Last Modified: 20 Apr 2025

    TablePress prior to version 1.8.1 allows an attacker to conduct XML External Entity (XXE) attacks via unspecified vectors.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-4927

    Last Modified: 20 Apr 2025

    VMware vCenter Server (6.5 prior to 6.5 U1 and 6.0 prior to 6.0 U3c) does not correctly handle specially crafted LDAP network packets which may allow for remote denial of service.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-4928

    Last Modified: 20 Apr 2025

    The flash-based vSphere Web Client (6.0 prior to 6.0 U3c and 5.5 prior to 5.5 U3f) i.e. not the new HTML5-based vSphere Client, contains SSRF and CRLF injection issues due to improper neutralization of URLs. An attacker may exploit these issues by sending a POST request with modified headers towards internal services leading to information disclosure.

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-4929

    Last Modified: 20 Apr 2025

    VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.

    Published: 17 Nov 2017
    8.8
    High

    CVE-2017-4934

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-4935

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds write vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View Client.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-4936

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-4937

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x before 12.5.8) and Horizon View Client for Windows (4.x before 4.6.1) contain an out-of-bounds read vulnerability in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View Client.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-10886

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Nov 2017
    4.6
    Medium

    CVE-2017-10890

    Last Modified: 20 Apr 2025

    Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows an attacker on the same LAN to perform arbitrary operations or access information via unspecified vectors.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-16872

    Last Modified: 20 Apr 2025

    An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing unintended values to be captured or, if the values were subsequently converted back to strings, a buffer overrun. This will lead to a potential exploit using carefully crafted invalid values.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-16869

    Last Modified: 20 Apr 2025

    p_mach.cpp in UPX 3.94 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted Mach-O file, related to canPack and unpack functions. NOTE: the vendor has stated "there is no security implication whatsoever.

    Published: 17 Nov 2017
    8.1
    High

    CVE-2017-16870

    Last Modified: 20 Apr 2025

    The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary

    Published: 17 Nov 2017
    8.1
    High

    CVE-2017-16871

    Last Modified: 20 Apr 2025

    The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundary

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-16868

    Last Modified: 20 Apr 2025

    In SWFTools 0.9.2, the wav_convert2mono function in lib/wav.c does not properly restrict a multiplication within a malloc call, which allows remote attackers to cause a denial of service (integer overflow and NULL pointer dereference) via a crafted WAV file.

    Published: 17 Nov 2017
    5.3
    Medium

    CVE-2017-1000226

    Last Modified: 23 Jan 2026

    Stop User Enumeration 1.3.8 allows user enumeration via the REST API

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000129

    Last Modified: 20 Apr 2025

    Serendipity 2.0.3 is vulnerable to a SQL injection in the blog component resulting in information disclosure

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000223

    Last Modified: 20 Apr 2025

    A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.

    Published: 17 Nov 2017