CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-5130

    Last Modified: 3 Dec 2025

    An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted XML file.

    Published: 17 Oct 2017
    7.8
    High

    CVE-2017-15385

    Last Modified: 20 Apr 2025

    The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2017-9367

    Last Modified: 20 Apr 2025

    A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST request.

    Published: 16 Oct 2017
    7.5
    High

    CVE-2017-9368

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-0316

    Last Modified: 20 Apr 2025

    In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15221

    Last Modified: 20 Apr 2025

    ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2015-7687

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2015-2780

    Last Modified: 20 Apr 2025

    Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 16 Oct 2017
    5.9
    Medium

    CVE-2015-3229

    Last Modified: 20 Apr 2025

    fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2015-4650

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.

    Published: 16 Oct 2017
    5.9
    Medium

    CVE-2017-15361

    Last Modified: 20 Apr 2025

    The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15383

    Last Modified: 20 Apr 2025

    Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGRAMFILES(x86)%\Nero directory.

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2017-15384

    Last Modified: 20 Apr 2025

    rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.

    Published: 16 Oct 2017
    8.8
    High

    CVE-2016-4461

    Last Modified: 20 Apr 2025

    Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0785.

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2017-15294

    Last Modified: 20 Apr 2025

    The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

    Published: 16 Oct 2017
    7.5
    High

    CVE-2017-15297

    Last Modified: 20 Apr 2025

    SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2017-15293

    Last Modified: 20 Apr 2025

    Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal read operations, or certain attacks on credentials. This is SAP Security Note 2520064.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2017-15295

    Last Modified: 20 Apr 2025

    Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 2520064.

    Published: 16 Oct 2017
    8.8
    High

    CVE-2017-15296

    Last Modified: 20 Apr 2025

    The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.

    Published: 16 Oct 2017
    7.5
    High

    CVE-2014-9147

    Last Modified: 20 Apr 2025

    Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2014-9148

    Last Modified: 20 Apr 2025

    Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2014-8087

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the txt parameter in a headline action to ajax/ph_save.php.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2014-8621

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2017-15374

    Last Modified: 20 Apr 2025

    Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent execution in the customer and orders section of the backend. The execution occurs in the administrator backend listing when processing a preview of the customers (kunden) or orders (bestellungen). The injection can be performed interactively via user registration or by manipulation of the order information inputs. The issue can be exploited by low privileged user accounts against higher privileged (admin or moderator) accounts.

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2017-15375

    Last Modified: 20 Apr 2025

    Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, and `wpjb-membership` modules. Remote attackers are able to inject malicious script code to hijack admin session credentials via the backend, or to manipulate the backend on client-side performed requests. The attack vector is non-persistent and the request method to inject is GET. The attacker does not need a privileged user account to perform a successful exploitation.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2017-15376

    Last Modified: 20 Apr 2025

    The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.

    Published: 16 Oct 2017
    9.8
    Critical

    CVE-2017-15373

    Last Modified: 20 Apr 2025

    E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15303

    Last Modified: 20 Apr 2025

    In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).

    Published: 16 Oct 2017
    6.1
    Medium

    CVE-2017-15362

    Last Modified: 20 Apr 2025

    osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, injection of iframes to establish communication channels, etc. The vulnerability is present after login into the application. This affects a different tickets.php file than CVE-2015-1176.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15369

    Last Modified: 20 Apr 2025

    The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a register, which allows remote attackers to cause a denial of service (Fitz fz_drop_imp use-after-free and application crash) or possibly have unspecified other impact via a crafted PDF document.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15302

    Last Modified: 20 Apr 2025

    In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version 1.43) that can result in information disclosure or elevation of privileges, because of an arbitrary read of any physical address via ioctl 0x9C402604. Any application running on the system (Windows), including sandboxed users, can issue an ioctl to this driver without any validation. Furthermore, the driver can map any physical page on the system and returns the allocated map page address to the user: that results in an information leak and EoP. NOTE: the vendor indicates that the arbitrary read itself is intentional behavior (for ACPI scan functionality); the security issue is the lack of an ACL.

    Published: 16 Oct 2017
    7.8
    High

    CVE-2017-15368

    Last Modified: 20 Apr 2025

    The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13087

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

    Published: 16 Oct 2017
    6.8
    Medium

    CVE-2017-13086

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

    Published: 16 Oct 2017
    6.8
    Medium

    CVE-2017-13077

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

    Published: 16 Oct 2017
    8.1
    High

    CVE-2017-8028

    Last Modified: 20 Apr 2025

    In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.

    Published: 16 Oct 2017
    8.1
    High

    CVE-2017-1000256

    Last Modified: 20 Apr 2025

    libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13079

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13088

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

    Published: 16 Oct 2017
    4.7
    Medium

    CVE-2017-16355

    Last Modified: 20 Apr 2025

    In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is possible to list the contents of arbitrary files on a system by symlinking a file named REVISION from the application root folder to a file of choice and querying passenger-status --show=xml.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-18248

    Last Modified: 21 Nov 2024

    The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote attackers by sending print jobs with an invalid username, related to a D-Bus notification.

    Published: 16 Oct 2017
    8.8
    High

    CVE-2017-11292

    Last Modified: 22 Apr 2026

    Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbitrary code execution.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13078

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13080

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

    Published: 16 Oct 2017
    5.3
    Medium

    CVE-2017-13081

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.

    Published: 16 Oct 2017
    8.1
    High

    CVE-2017-13082

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

    Published: 16 Oct 2017
    6.8
    Medium

    CVE-2017-13084

    Last Modified: 20 Apr 2025

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.

    Published: 16 Oct 2017
    7.5
    High

    CVE-2017-15363

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.

    Published: 15 Oct 2017
    5.5
    Medium

    CVE-2017-15364

    Last Modified: 20 Apr 2025

    The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact via a crafted file. NOTE: This has been disputed and it is argued that this is not present in version 1.1.0.

    Published: 15 Oct 2017
    5.4
    Medium

    CVE-2017-15360

    Last Modified: 20 Apr 2025

    PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, related to incorrect error handling for an HTML encoded script.

    Published: 15 Oct 2017