CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-16638

    Last Modified: 20 Apr 2025

    The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a directory on which "chown" is called recursively by the OpenRC service script.

    Published: 6 Nov 2017
    7.1
    High

    CVE-2017-6331

    Last Modified: 20 Apr 2025

    Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.

    Published: 6 Nov 2017
    4.9
    Medium

    CVE-2017-14023

    Last Modified: 20 Apr 2025

    An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attacker who is a member of the administrators group to crash services by sending specially crafted messages to the DCOM interface.

    Published: 6 Nov 2017
    7.5
    High

    CVE-2017-12719

    Last Modified: 20 Apr 2025

    An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. A remote attacker is able to execute code to dereference a pointer within the program causing the application to become unavailable.

    Published: 6 Nov 2017
    6.3
    Medium

    CVE-2017-14016

    Last Modified: 20 Apr 2025

    A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

    Published: 6 Nov 2017
    7.8
    High

    CVE-2017-14029

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in Trihedral VTScada 11.3.03 and prior. The program will execute specially crafted malicious dll files placed on the target machine.

    Published: 6 Nov 2017
    5.5
    Medium

    CVE-2017-14025

    Last Modified: 20 Apr 2025

    An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowing a local attacker to provide a malicious parameter to the script that is not validated by the application, This could enable the attacker to retrieve any file on the server.

    Published: 6 Nov 2017
    7.8
    High

    CVE-2017-14031

    Last Modified: 20 Apr 2025

    An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.

    Published: 6 Nov 2017
    5.4
    Medium

    CVE-2017-16635

    Last Modified: 20 Apr 2025

    In TinyWebGallery v2.4, an XSS vulnerability is located in the `mkname`, `mkitem`, and `item` parameters of the `Add/Create` module. Remote attackers with low-privilege user accounts for backend access are able to inject malicious script codes into the `TWG Explorer` item listing. The request method to inject is POST and the attack vector is located on the application-side of the service. The injection point is the add/create input field and the execution point occurs in the item listing after the add or create.

    Published: 6 Nov 2017
    5.4
    Medium

    CVE-2017-16636

    Last Modified: 20 Apr 2025

    In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located in the new page, new category, and edit post function body message context. Remote attackers are able to bypass the basic editor validation to trigger cross site scripting. The XSS is persistent and the request method to inject via editor is GET. To save the editor context, the followup POST method request must be processed to perform the attack via the application side. The basic validation of the editor does not allow injecting script codes and blocks the context. Attackers can inject the code by using an editor tag that is not recognized by the basic validation. Thus allows a restricted user account to inject malicious script code to perform a persistent attack against higher privilege web-application user accounts.

    Published: 6 Nov 2017
    4.4
    Medium

    CVE-2017-16637

    Last Modified: 20 Apr 2025

    In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11, when resetting the network data via the software client, with a running VPN connection, a critical error occurs which leads to a "FrmAdvancedProtection" crash. Although the mechanism malfunctions and an error occurs during the runtime with the stack trace being issued, the software process is not properly terminated. The software client is still attempting to maintain the connection even though the network connection information is being reset live. In that insecure mode, the "FrmAdvancedProtection" component crashes, but the process continues to run with different errors and process corruptions. This local corruption vulnerability can be exploited by local attackers.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-15672

    Last Modified: 20 Apr 2025

    The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.

    Published: 6 Nov 2017
    5.4
    Medium

    CVE-2015-7878

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via taxonomy vocabulary and term names.

    Published: 6 Nov 2017
    7.5
    High

    CVE-2017-11177

    Last Modified: 20 Apr 2025

    TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.

    Published: 6 Nov 2017
    7.8
    High

    CVE-2017-16001

    Last Modified: 20 Apr 2025

    In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.

    Published: 6 Nov 2017
    7.6
    High

    CVE-2017-7425

    Last Modified: 20 Apr 2025

    Multiple potential reflected XSS issues exist in NetIQ iManager versions before 2.7.7 Patch 10 HF2 and 3.0.3.2.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-16524

    Last Modified: 20 Apr 2025

    Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory. To authenticate for this attack, one can obtain web-interface credentials in cleartext by leveraging the existing Local File Read Vulnerability referenced as CVE-2015-8279, which allows remote attackers to read the web-interface credentials via a request for the cslog_export.php?path=/root/php_modules/lighttpd/sbin/userpw URI.

    Published: 6 Nov 2017
    4.8
    Medium

    CVE-2017-15039

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) exists in Zurmo 3.2.1.57987acc3018 via a data: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.

    Published: 6 Nov 2017
    8
    High

    CVE-2017-16563

    Last Modified: 20 Apr 2025

    Cross-Site Request Forgery (CSRF) in the Basic Settings screen on Vonage (Grandstream) HT802 devices allows attackers to modify settings, related to cgi-bin/update.

    Published: 6 Nov 2017
    5.4
    Medium

    CVE-2017-16564

    Last Modified: 20 Apr 2025

    Stored Cross-site scripting (XSS) vulnerability in /cgi-bin/config2 on Vonage (Grandstream) HT802 devices allows remote authenticated users to inject arbitrary web script or HTML via the DHCP vendor class ID field (P148).

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-16565

    Last Modified: 20 Apr 2025

    Cross-Site Request Forgery (CSRF) in /cgi-bin/login on Vonage (Grandstream) HT802 devices allows attackers to authenticate a user via the login screen using the default password of 123 and submit arbitrary requests.

    Published: 6 Nov 2017
    4.8
    Medium

    CVE-2017-16569

    Last Modified: 20 Apr 2025

    An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-16570

    Last Modified: 20 Apr 2025

    KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-16547

    Last Modified: 20 Apr 2025

    The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 6 Nov 2017
    6.6
    Medium

    CVE-2017-16649

    Last Modified: 20 Apr 2025

    The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 6 Nov 2017
    8.1
    High

    CVE-2017-15114

    Last Modified: 20 Apr 2025

    When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it could, combined with this flaw, be exploited to escalate privileges to gain control over compute nodes.

    Published: 6 Nov 2017
    9.8
    Critical

    CVE-2017-15398

    Last Modified: 21 Nov 2024

    A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-15399

    Last Modified: 21 Nov 2024

    A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 6 Nov 2017
    6.6
    Medium

    CVE-2017-16650

    Last Modified: 20 Apr 2025

    The qmi_wwan_bind function in drivers/net/usb/qmi_wwan.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (divide-by-zero error and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-9096

    Last Modified: 20 Apr 2025

    The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

    Published: 6 Nov 2017
    5.5
    Medium

    CVE-2017-15306

    Last Modified: 20 Apr 2025

    The kvm_vm_ioctl_check_extension function in arch/powerpc/kvm/powerpc.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a KVM_CHECK_EXTENSION KVM_CAP_PPC_HTM ioctl call to /dev/kvm.

    Published: 6 Nov 2017
    8.8
    High

    CVE-2017-16545

    Last Modified: 20 Apr 2025

    The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.

    Published: 5 Nov 2017
    8.8
    High

    CVE-2017-16542

    Last Modified: 20 Apr 2025

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

    Published: 5 Nov 2017
    9.8
    Critical

    CVE-2017-16543

    Last Modified: 20 Apr 2025

    Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated by a crafted viewProps yCanvas field or viewid parameter.

    Published: 5 Nov 2017
    7.5
    High

    CVE-2017-16540

    Last Modified: 20 Apr 2025

    OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR site to an arbitrary attacker-controlled MySQL server via vectors involving a crafted state parameter.

    Published: 4 Nov 2017
    8.8
    High

    CVE-2017-16546

    Last Modified: 20 Apr 2025

    The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

    Published: 4 Nov 2017
    5.5
    Medium

    CVE-2017-17087

    Last Modified: 20 Apr 2025

    fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.

    Published: 4 Nov 2017
    6.5
    Medium

    CVE-2017-1000131

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to users staying logged in to their Mahara account even when they have been logged out of Moodle (when using MNet) as Mahara did not properly implement one of the MNet SSO API functions.

    Published: 3 Nov 2017
    4.8
    Medium

    CVE-2017-1000132

    Last Modified: 20 Apr 2025

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to a maliciously created .swf files that can have its code executed when a user tries to download the file.

    Published: 3 Nov 2017
    7.5
    High

    CVE-2017-1000133

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's artefacts to be included in a Leap2a export of their own pages.

    Published: 3 Nov 2017
    9.8
    Critical

    CVE-2017-1000152

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.

    Published: 3 Nov 2017
    6.5
    Medium

    CVE-2017-1000156

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to a group's configuration page being editable by any group member even when they didn't have the admin role.

    Published: 3 Nov 2017
    8.1
    High

    CVE-2017-1000134

    Last Modified: 20 Apr 2025

    Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to the group files they uploaded if another group member changes the access permissions on them.

    Published: 3 Nov 2017
    6.5
    Medium

    CVE-2017-1000142

    Last Modified: 20 Apr 2025

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.

    Published: 3 Nov 2017
    8.8
    High

    CVE-2017-1000148

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to PHP code execution as Mahara would pass portions of the XML through the PHP "unserialize()" function when importing a skin from an XML file.

    Published: 3 Nov 2017
    5.4
    Medium

    CVE-2017-1000149

    Last Modified: 20 Apr 2025

    Mahara 1.10 before 1.10.9 and 15.04 before 15.04.6 and 15.10 before 15.10.2 are vulnerable to XSS due to window.opener (target="_blank" and window.open())

    Published: 3 Nov 2017
    4.4
    Medium

    CVE-2017-1000157

    Last Modified: 20 Apr 2025

    Mahara 15.04 before 15.04.13 and 16.04 before 16.04.7 and 16.10 before 16.10.4 and 17.04 before 17.04.2 are vulnerable to recording plain text passwords in the event_log table during the user creation process if full event logging was turned on.

    Published: 3 Nov 2017
    6.5
    Medium

    CVE-2017-1000135

    Last Modified: 20 Apr 2025

    Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable as logged-in users can stay logged in after the institution they belong to is suspended.

    Published: 3 Nov 2017
    6.5
    Medium

    CVE-2017-1000136

    Last Modified: 20 Apr 2025

    Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable to old sessions not being invalidated after a password change.

    Published: 3 Nov 2017
    5.4
    Medium

    CVE-2017-1000137

    Last Modified: 20 Apr 2025

    Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).

    Published: 3 Nov 2017