CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-15908

    Last Modified: 20 Apr 2025

    In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

    Published: 26 Oct 2017
    7.8
    High

    CVE-2017-9806

    Last Modified: 20 Apr 2025

    A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary code execution.

    Published: 26 Oct 2017
    5.4
    Medium

    CVE-2017-1169

    Last Modified: 20 Apr 2025

    IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123188.

    Published: 25 Oct 2017
    5.4
    Medium

    CVE-2017-1164

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123036.

    Published: 25 Oct 2017
    4.3
    Medium

    CVE-2017-1241

    Last Modified: 20 Apr 2025

    An unspecified vulnerability in IBM Jazz Foundation based applications might allow the display of stack trace information to an attacker. IBM X-Force ID: 124523.

    Published: 25 Oct 2017
    4.3
    Medium

    CVE-2017-1295

    Last Modified: 20 Apr 2025

    IBM RSA DM contains unspecified vulnerability in CLM Applications with potential for information leakage. IBM X-Force ID: 125157.

    Published: 25 Oct 2017
    5.4
    Medium

    CVE-2017-1363

    Last Modified: 20 Apr 2025

    IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126856.

    Published: 25 Oct 2017
    7.8
    High

    CVE-2017-12705

    Last Modified: 20 Apr 2025

    A Heap-Based Buffer Overflow issue was discovered in Advantech WebOP. A maliciously crafted project file may be able to trigger a heap-based buffer overflow, which may crash the process and allow an attacker to execute arbitrary code.

    Published: 25 Oct 2017
    6.1
    Medium

    CVE-2017-15885

    Last Modified: 20 Apr 2025

    Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.

    Published: 25 Oct 2017
    9.8
    Critical

    CVE-2017-15088

    Last Modified: 20 Apr 2025

    plugins/preauth/pkinit/pkinit_crypto_openssl.c in MIT Kerberos 5 (aka krb5) through 1.15.2 mishandles Distinguished Name (DN) fields, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) in situations involving untrusted X.509 data, related to the get_matching_data and X509_NAME_oneline_ex functions. NOTE: this has security relevance only in use cases outside of the MIT Kerberos distribution, e.g., the use of get_matching_data in KDC certauth plugin code that is specific to Red Hat.

    Published: 25 Oct 2017
    7.2
    High

    CVE-2017-15880

    Last Modified: 20 Apr 2025

    SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the group_name parameter to module/admin_group/add_modify_group.php (for insert_group and update_group).

    Published: 24 Oct 2017
    4.8
    Medium

    CVE-2017-15881

    Last Modified: 20 Apr 2025

    Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.

    Published: 24 Oct 2017
    6.5
    Medium

    CVE-2017-1212

    Last Modified: 20 Apr 2025

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.

    Published: 24 Oct 2017
    5.4
    Medium

    CVE-2016-3049

    Last Modified: 20 Apr 2025

    IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 114712.

    Published: 24 Oct 2017
    5.4
    Medium

    CVE-2017-1209

    Last Modified: 20 Apr 2025

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123849.

    Published: 24 Oct 2017
    2.5
    Low

    CVE-2017-1211

    Last Modified: 20 Apr 2025

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-1375

    Last Modified: 20 Apr 2025

    IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 126868.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-1523

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-1583

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by improper error handling by MyFaces in JSF.

    Published: 24 Oct 2017
    6.1
    Medium

    CVE-2017-15878

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.

    Published: 24 Oct 2017
    8.8
    High

    CVE-2017-15879

    Last Modified: 20 Apr 2025

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before 4.0.0-beta.7 via a value that is mishandled in a CSV export.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-1210

    Last Modified: 20 Apr 2025

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-15871

    Last Modified: 20 Apr 2025

    The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function()" substring, as demonstrated by a "function(){console.log(" call or a simple infinite loop. NOTE: the vendor agrees that denial of service can occur but notes that deserialize is explicitly listed as "harmful" within the README.md file

    Published: 24 Oct 2017
    4.8
    Medium

    CVE-2017-15872

    Last Modified: 20 Apr 2025

    phpwcms 1.8.9 has XSS in include/inc_tmpl/admin.edituser.tmpl.php and include/inc_tmpl/admin.newuser.tmpl.php via the username (aka new_login) field.

    Published: 24 Oct 2017
    6.1
    Medium

    CVE-2017-15867

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name, (6) browser, (7) operating_system, or (8) ip_address parameter to admin/partials/listing/listing.php.

    Published: 24 Oct 2017
    6.1
    Medium

    CVE-2017-15863

    Last Modified: 20 Apr 2025

    Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.

    Published: 24 Oct 2017
    8.8
    High

    CVE-2015-5170

    Last Modified: 20 Apr 2025

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2015-5171

    Last Modified: 20 Apr 2025

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2015-5172

    Last Modified: 20 Apr 2025

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

    Published: 24 Oct 2017
    8.8
    High

    CVE-2015-5173

    Last Modified: 20 Apr 2025

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2017-15222

    Last Modified: 20 Apr 2025

    Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.

    Published: 24 Oct 2017
    5.3
    Medium

    CVE-2017-15223

    Last Modified: 20 Apr 2025

    Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.

    Published: 24 Oct 2017
    6.5
    Medium

    CVE-2017-15186

    Last Modified: 20 Apr 2025

    Double free vulnerability in FFmpeg 3.3.4 and earlier allows remote attackers to cause a denial of service via a crafted AVI file.

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2014-1203

    Last Modified: 20 Apr 2025

    The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.

    Published: 24 Oct 2017
    7.3
    High

    CVE-2014-0691

    Last Modified: 20 Apr 2025

    Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643.

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2017-15081

    Last Modified: 20 Apr 2025

    In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

    Published: 24 Oct 2017
    9.1
    Critical

    CVE-2017-15597

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not match up with that assumption. When such a grant copy operation is being done on a grant of a dying domain, the assumption turns out wrong. A malicious guest administrator can cause hypervisor memory corruption, most likely resulting in host crash and a Denial of Service. Privilege escalation and information leaks cannot be ruled out.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-15938

    Last Modified: 20 Apr 2025

    dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in the case of a relocatable object file, which allows remote attackers to cause a denial of service (find_abstract_instance_name invalid memory read, segmentation fault, and application crash).

    Published: 24 Oct 2017
    9.8
    Critical

    CVE-2017-15994

    Last Modified: 20 Apr 2025

    rsync 3.1.3-development before 2017-10-24 mishandles archaic checksums, which makes it easier for remote attackers to bypass intended access restrictions. NOTE: the rsync development branch has significant use beyond the rsync developers, e.g., the code has been copied for use in various GitHub projects.

    Published: 24 Oct 2017
    5.9
    Medium

    CVE-2017-15085

    Last Modified: 20 Apr 2025

    It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

    Published: 24 Oct 2017
    7.4
    High

    CVE-2017-15086

    Last Modified: 20 Apr 2025

    It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-15087

    Last Modified: 20 Apr 2025

    It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

    Published: 24 Oct 2017
    7.5
    High

    CVE-2017-14919

    Last Modified: 20 Apr 2025

    Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

    Published: 24 Oct 2017
    6.6
    Medium

    CVE-2017-16643

    Last Modified: 20 Apr 2025

    The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 24 Oct 2017
    5.7
    Medium

    CVE-2017-13682

    Last Modified: 20 Apr 2025

    In Symantec Encryption Desktop before SED 10.4.1 MP2HF1, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented programming, a memory leak may happen when an object is stored in memory but cannot be accessed by the running code.

    Published: 23 Oct 2017
    5.7
    Medium

    CVE-2017-13683

    Last Modified: 20 Apr 2025

    In Symantec Endpoint Encryption before SEE 11.1.3HF3, a kernel memory leak is a type of resource leak that can occur when a computer program incorrectly manages memory allocations in such a way that memory which is no longer needed is not released. In object-oriented programming, a memory leak may happen when an object is stored in memory but cannot be accessed by the running code.

    Published: 23 Oct 2017
    8.8
    High

    CVE-2015-2878

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP Redirect Sensor in a request to interface/rest/dpi/setEnabled/1; or (5) perform whitelisting of malware MD5 hash IDs via the id parameter to interface/rest/md5-threats/whitelist.

    Published: 23 Oct 2017
    6.1
    Medium

    CVE-2015-5532

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php, or (3) orders.php in adminpages/ or the (4) edit parameter to adminpages/membershiplevels.php.

    Published: 23 Oct 2017
    9.8
    Critical

    CVE-2014-3741

    Last Modified: 20 Apr 2025

    The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.

    Published: 23 Oct 2017
    5.9
    Medium

    CVE-2011-2683

    Last Modified: 20 Apr 2025

    reseed seeds random numbers from an insecure HTTP request to random.org during installation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a man-in-the-middle attack.

    Published: 23 Oct 2017