CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-16760

    Last Modified: 20 Apr 2025

    Inedo BuildMaster before 5.8.2 has XSS.

    Published: 10 Nov 2017
    9.8
    Critical

    CVE-2017-16521

    Last Modified: 20 Apr 2025

    In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.

    Published: 10 Nov 2017
    9.8
    Critical

    CVE-2017-16764

    Last Modified: 20 Apr 2025

    An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in django_make_app 0.1.3. A YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.

    Published: 10 Nov 2017
    6.1
    Medium

    CVE-2017-16761

    Last Modified: 20 Apr 2025

    An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary web sites.

    Published: 10 Nov 2017
    7.5
    High

    CVE-2017-16762

    Last Modified: 20 Apr 2025

    Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substring.

    Published: 10 Nov 2017
    9.8
    Critical

    CVE-2017-16763

    Last Modified: 20 Apr 2025

    An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being loaded from "~/.confire.yaml" using the yaml.load function, a YAML parser can execute arbitrary Python commands resulting in command execution. An attacker can insert Python into loaded YAML to trigger this vulnerability.

    Published: 10 Nov 2017
    8.1
    High

    CVE-2018-1307

    Last Modified: 21 Nov 2024

    In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD type of attacks. Mitigation is to use 3.3.5.

    Published: 10 Nov 2017
    4.8
    Medium

    CVE-2017-16758

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "access_token" parameter.

    Published: 9 Nov 2017
    5.9
    Medium

    CVE-2017-16759

    Last Modified: 20 Apr 2025

    The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.

    Published: 9 Nov 2017
    7.8
    High

    CVE-2017-16757

    Last Modified: 20 Apr 2025

    Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.

    Published: 9 Nov 2017
    9.8
    Critical

    CVE-2017-16562

    Last Modified: 20 Apr 2025

    The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value for the up_auto_log parameter in the QUERY_STRING to the default URI.

    Published: 9 Nov 2017
    5.4
    Medium

    CVE-2017-16567

    Last Modified: 20 Apr 2025

    Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected functionality. Exploitation of this vulnerability can lead to Session Hijacking and Credential Theft, Execution of unauthorized actions on behalf of users, and Exfiltration of sensitive data. This vulnerability presents a potential risk for widespread exploitation in connected IoT environments.

    Published: 9 Nov 2017
    9.8
    Critical

    CVE-2017-16634

    Last Modified: 20 Apr 2025

    In Joomla! before 3.8.2, a bug allowed third parties to bypass a user's 2-factor authentication method.

    Published: 9 Nov 2017
    9.6
    Critical

    CVE-2017-11309

    Last Modified: 20 Apr 2025

    Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

    Published: 9 Nov 2017
    4.3
    Medium

    CVE-2017-11461

    Last Modified: 20 Apr 2025

    NetApp OnCommand Unified Manager for 7-mode (core package) versions prior to 5.2.1 are susceptible to a clickjacking or "UI redress attack" which could be used to cause a user to perform an unintended action in the user interface.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12779

    Last Modified: 20 Apr 2025

    The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12780

    Last Modified: 20 Apr 2025

    The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12781

    Last Modified: 20 Apr 2025

    The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12782

    Last Modified: 20 Apr 2025

    The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12783

    Last Modified: 20 Apr 2025

    The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12801

    Last Modified: 20 Apr 2025

    The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12802

    Last Modified: 20 Apr 2025

    The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12803

    Last Modified: 20 Apr 2025

    The Node_ValidatePtr function in corec/corec/node/node.c in mkclean 0.8.9 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.

    Published: 9 Nov 2017
    8.8
    High

    CVE-2017-12969

    Last Modified: 20 Apr 2025

    Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-15638

    Last Modified: 20 Apr 2025

    The SuSEfirewall2 package before 3.6.312-2.13.1 in SUSE Linux Enterprise (SLE) Desktop 12 SP2, Server 12 SP2, and Server for Raspberry Pi 12 SP2; before 3.6.312.333-3.10.1 in SLE Desktop 12 SP3 and Server 12 SP3; before 3.6_SVNr208-2.18.3.1 in SLE Server 11 SP4; before 3.6.312-5.9.1 in openSUSE Leap 42.2; and before 3.6.312.333-7.1 in openSUSE Leap 42.3 might allow remote attackers to bypass intended access restrictions on the portmap service by leveraging a missing source net restriction for _rpc_ services.

    Published: 9 Nov 2017
    7.5
    High

    CVE-2017-16249

    Last Modified: 20 Apr 2025

    The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.

    Published: 9 Nov 2017
    4.3
    Medium

    CVE-2017-16633

    Last Modified: 20 Apr 2025

    In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.

    Published: 9 Nov 2017
    5.3
    Medium

    CVE-2017-16754

    Last Modified: 20 Apr 2025

    Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServiceProvider.php.

    Published: 9 Nov 2017
    5.7
    Medium

    CVE-2017-5201

    Last Modified: 20 Apr 2025

    NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors, a different vulnerability than CVE-2016-3064.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-12800

    Last Modified: 20 Apr 2025

    The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.

    Published: 9 Nov 2017
    5.4
    Medium

    CVE-2017-16568

    Last Modified: 20 Apr 2025

    Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation of this vulnerability can lead to Session hijacking and unauthorized access, Persistent manipulation of web content within the application, and Phishing or malicious redirects to external domains. This vulnerability can be exploited to manipulate media server behavior in enterprise and home network environments.

    Published: 9 Nov 2017
    7.4
    High

    CVE-2017-9758

    Last Modified: 20 Apr 2025

    Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Authorities store, aka "Inaudible Subversion."

    Published: 9 Nov 2017
    5.5
    Medium

    CVE-2017-16711

    Last Modified: 20 Apr 2025

    The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefinitions in lib/readers/swf.c and fill_line_bitmap in lib/devices/render.c, as demonstrated by swfrender.

    Published: 9 Nov 2017
    7.8
    High

    CVE-2017-16651

    Last Modified: 21 Apr 2026

    Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.

    Published: 9 Nov 2017
    8
    High

    CVE-2017-16674

    Last Modified: 20 Apr 2025

    Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command and a secondary non-whitelisted command. This affects Datto Windows Agent (DWA) 1.0.5.0 and earlier. In other words, an attacker could combine this "primary/secondary" attack with the CVE-2017-16673 "rogue pairing" attack to achieve unauthenticated access to all agent machines running these older DWA versions.

    Published: 9 Nov 2017
    5.3
    Medium

    CVE-2017-16673

    Last Modified: 20 Apr 2025

    Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to "pair" with the agent and issue requests to this agent, if the attacker can reach the agent on TCP port 25566 or 25568, and send unspecified "specific information" by which the agent identifies a network device that is "appearing to be a valid Datto."

    Published: 9 Nov 2017
    7.3
    High

    CVE-2017-1000391

    Last Modified: 21 Nov 2024

    Jenkins versions 2.88 and earlier and 2.73.2 and earlier stores metadata related to 'people', which encompasses actual user accounts, as well as users appearing in SCM, in directories corresponding to the user ID on disk. These directories used the user ID for their name without additional escaping, potentially resulting in problems like overwriting of unrelated configuration files.

    Published: 9 Nov 2017
    5.9
    Medium

    CVE-2017-16672

    Last Modified: 20 Apr 2025

    An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. A memory leak occurs when an Asterisk pjsip session object is created and that call gets rejected before the session itself is fully established. When this happens the session object never gets destroyed. Eventually Asterisk can run out of memory and crash.

    Published: 9 Nov 2017
    8.1
    High

    CVE-2017-15098

    Last Modified: 20 Apr 2025

    Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

    Published: 9 Nov 2017
    6.5
    Medium

    CVE-2017-15099

    Last Modified: 20 Apr 2025

    INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

    Published: 9 Nov 2017
    8.8
    High

    CVE-2017-16669

    Last Modified: 20 Apr 2025

    coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.

    Published: 9 Nov 2017
    4.8
    Medium

    CVE-2017-1000392

    Last Modified: 21 Nov 2024

    Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

    Published: 9 Nov 2017
    6.7
    Medium

    CVE-2017-12172

    Last Modified: 20 Apr 2025

    PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, 9.3.x before 9.3.20, and 9.2.x before 9.2.24 runs under a non-root operating system account, and database superusers have effective ability to run arbitrary code under that system account. PostgreSQL provides a script for starting the database server during system boot. Packages of PostgreSQL for many operating systems provide their own, packager-authored startup implementations. Several implementations use a log file name that the database superuser can replace with a symbolic link. As root, they open(), chmod() and/or chown() this log file name. This often suffices for the database superuser to escalate to root privileges when root starts the server.

    Published: 9 Nov 2017
    8.8
    High

    CVE-2017-16671

    Last Modified: 20 Apr 2025

    A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified Asterisk 13.13 before 13.13-cert7. No size checking is done when setting the user field for Party B on a CDR. Thus, it is possible for someone to use an arbitrarily large string and write past the end of the user field storage buffer. NOTE: this is different from CVE-2017-7617, which was only about the Party A buffer.

    Published: 9 Nov 2017
    7.5
    High

    CVE-2017-11512

    Last Modified: 20 Apr 2025

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

    Published: 8 Nov 2017
    7.5
    High

    CVE-2017-11511

    Last Modified: 20 Apr 2025

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

    Published: 8 Nov 2017
    7.5
    High

    CVE-2017-15865

    Last Modified: 20 Apr 2025

    bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

    Published: 8 Nov 2017
    Unknown

    CVE-2013-6055

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 8 Nov 2017
    7.8
    High

    CVE-2017-16667

    Last Modified: 20 Apr 2025

    backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.system call in qt4/plugins/notifyplugin.py. This could allow an attacker to craft an unreadable file with a specific name to run arbitrary shell commands.

    Published: 8 Nov 2017
    6.1
    Medium

    CVE-2017-16665

    Last Modified: 20 Apr 2025

    RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the service parameter to the /soap URI, triggering an invalid attempt to generate WSDL.

    Published: 8 Nov 2017