CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-1000229

    Last Modified: 20 Apr 2025

    Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000125

    Last Modified: 20 Apr 2025

    Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000164

    Last Modified: 20 Apr 2025

    Tine 2.0 version 2017.02.4 is vulnerable to XSS in the Addressbook resulting code execution and privilege escalation

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000160

    Last Modified: 20 Apr 2025

    EllisLab ExpressionEngine 3.4.2 is vulnerable to cross-site scripting resulting in PHP code injection

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-1000225

    Last Modified: 20 Apr 2025

    Reflected XSS in Relevanssi Premium version 1.14.8 when using relevanssi_didyoumean() could allow unauthenticated attacker to do almost anything an admin can

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000247

    Last Modified: 20 Apr 2025

    British Columbia Institute of Technology CodeIgniter 3.1.3 is vulnerable to HTTP Header Injection in the set_status_header() common function under Apache resulting in HTTP Header Injection flaws.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000237

    Last Modified: 5 Dec 2025

    I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000248

    Last Modified: 20 Apr 2025

    Redis-store <=v1.3.0 allows unsafe objects to be loaded from redis

    Published: 17 Nov 2017
    5.3
    Medium

    CVE-2017-1000234

    Last Modified: 5 Dec 2025

    I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker enumerating directories simply by navigating through the "dir" parameter

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000235

    Last Modified: 5 Dec 2025

    I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-1000236

    Last Modified: 5 Dec 2025

    I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacker being able to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000172

    Last Modified: 20 Apr 2025

    Creolabs Gravity Version: 1.0 Use-After-Free Possible code execution. An example of a Heap-Use-After-Free after the 'sublexer' pointer has been freed. Line 542 of gravity_lexer.c. 'lexer' is being used to access a variable but 'lexer' has already been freed, creating a Heap Use-After-Free condition.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000173

    Last Modified: 20 Apr 2025

    Creolabs Gravity Version: 1.0 Heap Overflow Potential Code Execution. By creating a large loop whiling pushing data to a buffer, we can break out of the bounds checking of that buffer. When list.join is called on the data it will read past a buffer resulting in a Heap-Buffer-Overflow.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000239

    Last Modified: 20 Apr 2025

    InvoicePlane version 1.4.10 is vulnerable to a Stored Cross Site Scripting resulting in allowing an authenticated user to inject malicious client side script which will be executed in the browser of users if they visit the manipulated site.

    Published: 17 Nov 2017
    5.4
    Medium

    CVE-2017-1000240

    Last Modified: 20 Apr 2025

    The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versions. These vulnerabilities could allow remote authenticated attackers to inject arbitrary web script or HTML.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000228

    Last Modified: 20 Apr 2025

    nodejs ejs versions older than 2.5.3 is vulnerable to remote code execution due to weak input validation in ejs.renderFile() function

    Published: 17 Nov 2017
    8.8
    High

    CVE-2017-1000238

    Last Modified: 20 Apr 2025

    InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.

    Published: 17 Nov 2017
    8.1
    High

    CVE-2017-1000241

    Last Modified: 20 Apr 2025

    The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow an authenticated non-administrator users to view and modify information only accessible to administrators.

    Published: 17 Nov 2017
    5.9
    Medium

    CVE-2017-1000209

    Last Modified: 20 Apr 2025

    The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.

    Published: 17 Nov 2017
    6.1
    Medium

    CVE-2017-1000193

    Last Modified: 20 Apr 2025

    October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000194

    Last Modified: 20 Apr 2025

    October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2017-1000195

    Last Modified: 20 Apr 2025

    October CMS build 412 is vulnerable to PHP object injection in asset move functionality resulting in ability to delete files limited by file permissions on the server.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000196

    Last Modified: 20 Apr 2025

    October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000197

    Last Modified: 20 Apr 2025

    October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.

    Published: 17 Nov 2017
    8.8
    High

    CVE-2017-1000208

    Last Modified: 20 Apr 2025

    A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-1000185

    Last Modified: 20 Apr 2025

    In SWFTools, a memcpy buffer overflow was found in gif2swf.

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-1000186

    Last Modified: 20 Apr 2025

    In SWFTools, a stack overflow was found in pdf2swf.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-1000187

    Last Modified: 20 Apr 2025

    In SWFTools, an address access exception was found in pdf2swf. FoFiTrueType::writeTTF()

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-1000182

    Last Modified: 20 Apr 2025

    In SWFTools, a memory leak was found in wav2swf.

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-1000174

    Last Modified: 20 Apr 2025

    In SWFTools, an address access exception was found in swfdump swf_GetBits().

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-1000176

    Last Modified: 20 Apr 2025

    In SWFTools, a memcpy buffer overflow was found in swfc.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000210

    Last Modified: 20 Apr 2025

    picoTCP (versions 1.7.0 - 1.5.0) is vulnerable to stack buffer overflow resulting in code execution or denial of service attack

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000220

    Last Modified: 20 Apr 2025

    soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution

    Published: 17 Nov 2017
    4.8
    Medium

    CVE-2017-1000213

    Last Modified: 20 Apr 2025

    WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search

    Published: 17 Nov 2017
    6.5
    Medium

    CVE-2017-1000224

    Last Modified: 20 Apr 2025

    CSRF in YouTube (WordPress plugin) could allow unauthenticated attacker to change any setting within the plugin

    Published: 17 Nov 2017
    6.5
    Medium

    CVE-2017-1000476

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2018-0764

    Last Modified: 21 Nov 2024

    Microsoft .NET Framework 1.1, 2.0, 3.0, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 5.7 and .NET Core 1.0. 1.1 and 2.0 allow a denial of service vulnerability due to the way XML documents are processed, aka ".NET and .NET Core Denial Of Service Vulnerability". This CVE is unique from CVE-2018-0765.

    Published: 17 Nov 2017
    7.5
    High

    CVE-2018-14884

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000219

    Last Modified: 20 Apr 2025

    npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user

    Published: 17 Nov 2017
    5.5
    Medium

    CVE-2017-15517

    Last Modified: 20 Apr 2025

    AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urged to move to a fixed version and change passwords used by Veritas NetBackup to access the OST shares on the NetApp AltaVault as a precaution.

    Published: 17 Nov 2017
    9.8
    Critical

    CVE-2017-1000218

    Last Modified: 8 Dec 2025

    LightFTP version 1.1 is vulnerable to a buffer overflow in the "writelogentry" function resulting a denial of services or a remote code execution.

    Published: 17 Nov 2017
    7.8
    High

    CVE-2017-0832

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62887820.

    Published: 16 Nov 2017
    7.5
    High

    CVE-2017-0840

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62948670.

    Published: 16 Nov 2017
    5.3
    Medium

    CVE-2017-0849

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62688399.

    Published: 16 Nov 2017
    7.5
    High

    CVE-2017-0858

    Last Modified: 20 Apr 2025

    Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.

    Published: 16 Nov 2017
    7.8
    High

    CVE-2017-0830

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62623498.

    Published: 16 Nov 2017
    7.8
    High

    CVE-2017-0834

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63125953.

    Published: 16 Nov 2017
    7.8
    High

    CVE-2017-0835

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.

    Published: 16 Nov 2017
    7.8
    High

    CVE-2017-0836

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64893226.

    Published: 16 Nov 2017
    7.8
    High

    CVE-2017-0838

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-63522818.

    Published: 16 Nov 2017