CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-14388

    Last Modified: 20 Apr 2025

    Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide an image layer that GrootFS would consider to be the Ubuntu base layer.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-3767

    Last Modified: 20 Apr 2025

    A local privilege escalation vulnerability was identified in the Realtek audio driver versions prior to 6.0.1.8224 in some Lenovo ThinkPad products. An attacker with local privileges could execute code with administrative privileges.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-9314

    Last Modified: 20 Apr 2025

    Authentication vulnerability found in Dahua NVR models NVR50XX, NVR52XX, NVR54XX, NVR58XX with software before DH_NVR5xxx_Eng_P_V2.616.0000.0.R.20171102. Attacker could exploit this vulnerability to gain access to additional operations by means of forging json message.

    Published: 13 Nov 2017
    Unknown

    CVE-2016-8234

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 13 Nov 2017
    5.4
    Medium

    CVE-2017-16802

    Last Modified: 20 Apr 2025

    In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.

    Published: 13 Nov 2017
    Unknown

    CVE-2012-2456

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-5174. Reason: This candidate is a reservation duplicate of CVE-2011-5174. Notes: All CVE users should reference CVE-2011-5174 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-10885

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in HYPER SBI Ver. 2.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2016-6803

    Last Modified: 20 Apr 2025

    An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3 installers for Windows. The PC must have previously been infected by a Trojan Horse application (or user) running with administrative privilege. Any installer with the unquoted search path vulnerability becomes a delayed trigger for the exploit.

    Published: 13 Nov 2017
    9.8
    Critical

    CVE-2017-10871

    Last Modified: 20 Apr 2025

    Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.

    Published: 13 Nov 2017
    7.5
    High

    CVE-2017-10875

    Last Modified: 20 Apr 2025

    I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-3166

    Last Modified: 20 Apr 2025

    In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it world readable is localized via YARN's localization mechanism, that file will be stored in a world-readable location and can be shared freely with any application that requests to localize that file.

    Published: 13 Nov 2017
    6.1
    Medium

    CVE-2017-7739

    Last Modified: 20 Apr 2025

    A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5.2.11 allows an unauthenticated attacker to inject arbitrary web script or HTML in the context of the victim's browser via sending a maliciously crafted URL to the victim.

    Published: 13 Nov 2017
    Unknown

    CVE-2017-0908

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-16510. Reason: This candidate is a reservation duplicate of CVE-2017-16510. Notes: All CVE users should reference CVE-2017-16510 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-11169

    Last Modified: 20 Apr 2025

    Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter to /form2userconfig.cgi.

    Published: 13 Nov 2017
    5.4
    Medium

    CVE-2017-16801

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-8806

    Last Modified: 20 Apr 2025

    The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debian and Ubuntu), handled symbolic links insecurely, which could result in local denial of service by overwriting arbitrary files.

    Published: 13 Nov 2017
    8.1
    High

    CVE-2017-14711

    Last Modified: 20 Apr 2025

    The Kickbase GmbH "Kickbase Bundesliga Manager" app before 2.2.1 -- aka kickbase-bundesliga-manager/id678241305 -- for iOS is vulnerable to a credentials leak due to transmitting a username and password in cleartext from client to server during registration and authentication.

    Published: 13 Nov 2017
    6.1
    Medium

    CVE-2017-16792

    Last Modified: 20 Apr 2025

    Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13785

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13793

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13813

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13834

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted mach binary.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13843

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    9.8
    Critical

    CVE-2017-13846

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "PCRE" product. Versions before 8.40 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 13 Nov 2017
    3.3
    Low

    CVE-2017-13852

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to monitor arbitrary apps via a crafted app that accesses process information at a high rate.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13799

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13800

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13849

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.

    Published: 13 Nov 2017
    4.6
    Medium

    CVE-2017-13786

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "APFS" component. It does not properly restrict the DMA mapping time of FileVault decryption buffers, which allows attackers to read cleartext APFS data via a crafted Thunderbolt adapter.

    Published: 13 Nov 2017
    6.5
    Medium

    CVE-2017-13790

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote attackers to spoof the address bar via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13792

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13795

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13796

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13797

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    8.8
    High

    CVE-2017-13798

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 13 Nov 2017
    3.3
    Low

    CVE-2017-13801

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Dictionary Widget" component. It allows attackers to read local files if pasted text is used in a search.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13804

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "StreamingZip" component. It allows remote attackers to write to unintended pathnames via a crafted ZIP archive.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13807

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption) via a crafted QuickTime file.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13808

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Remote Management" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13809

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "AppleScript" component. It allows remote attackers to execute arbitrary code via a crafted AppleScript file that is mishandled by osadecompile.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13810

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to obtain sensitive information by leveraging an error in packet counters.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13811

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "fsck_msdos" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13812

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted archive file.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13814

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted image file.

    Published: 13 Nov 2017
    9.8
    Critical

    CVE-2017-13815

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the third-party "file" product. Versions before 5.31 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 13 Nov 2017
    7.8
    High

    CVE-2017-13816

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "libarchive" component. It allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted archive file.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13817

    Last Modified: 20 Apr 2025

    An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13818

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017
    6.1
    Medium

    CVE-2017-13819

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "HelpViewer" component. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML by bypassing the Same Origin Policy for quarantined HTML documents.

    Published: 13 Nov 2017
    5.5
    Medium

    CVE-2017-13842

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published: 13 Nov 2017