CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-10865

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in HIBUN Confidential File Decryption program prior to 10.50.0.5 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Note this is a separate vulnerability from CVE-2017-10863.

    Published: 12 Oct 2017
    5.3
    Medium

    CVE-2017-10862

    Last Modified: 20 Apr 2025

    jwt-scala 1.2.2 and earlier fails to verify token signatures correctly which may lead to an attacker being able to pass specially crafted JWT data as a correctly signed token.

    Published: 12 Oct 2017
    7.8
    High

    CVE-2017-10864

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer of HIBUN Confidential File Viewer prior to 11.20.0001 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-9514

    Last Modified: 20 Apr 2025

    Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which classes could be loaded. An attacker who can log in to Bamboo as a user is able to exploit this vulnerability to execute Java code of their choice on systems that have vulnerable versions of Bamboo.

    Published: 12 Oct 2017
    5.4
    Medium

    CVE-2017-15284

    Last Modified: 20 Apr 2025

    Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.

    Published: 12 Oct 2017
    5.4
    Medium

    CVE-2017-15278

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) was discovered in TeamPass before 2.1.27.9. The vulnerability exists due to insufficient filtration of data (in /sources/folders.queries.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Oct 2017
    5.4
    Medium

    CVE-2017-15279

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Umbraco CMS before 7.7.3 allows remote attackers to inject arbitrary web script or HTML via the "page name" (aka nodename) parameter during the creation of a new page, related to Umbraco.Web.UI/umbraco/dialogs/Publish.aspx.cs and Umbraco.Web/umbraco.presentation/umbraco/dialogs/notifications.aspx.cs.

    Published: 12 Oct 2017
    5.5
    Medium

    CVE-2017-15280

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server or sending TCP requests to intranet hosts (aka SSRF), related to Umbraco.Web/umbraco.presentation/umbraco/dialogs/importDocumenttype.aspx.cs.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-15285

    Last Modified: 20 Apr 2025

    X-Cart 5.2.23, 5.3.1.9, 5.3.2.13, and 5.3.3 is vulnerable to Remote Code Execution. This vulnerability exists because the application fails to check remote file extensions before saving locally. This vulnerability can be exploited by anyone with Vendor access or higher. One attack methodology is to upload an image file in the Attachments section of a product catalog, upload a .php file with an "Add File Via URL" action, and change the image's Description URL to reference the .php URL in the attachments/ directory.

    Published: 12 Oct 2017
    5.5
    Medium

    CVE-2017-15298

    Last Modified: 20 Apr 2025

    Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected process typically would not survive its attempt to build the data structure in memory before writing to disk.

    Published: 12 Oct 2017
    7.5
    High

    CVE-2017-15286

    Last Modified: 20 Apr 2025

    SQLite 3.20.1 has a NULL pointer dereference in tableColumnList in shell.c because it fails to consider certain cases where `sqlite3_step(pStmt)==SQLITE_ROW` is false and a data structure is never initialized.

    Published: 12 Oct 2017
    7.8
    High

    CVE-2017-15588

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to execute arbitrary code on the host OS because of a race condition that can cause a stale TLB entry.

    Published: 12 Oct 2017
    6.5
    Medium

    CVE-2017-15589

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to obtain sensitive information from the host OS (or an arbitrary guest OS) because intercepted I/O operations can cause a write of data from uninitialized hypervisor stack memory.

    Published: 12 Oct 2017
    6.5
    Medium

    CVE-2017-15591

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen 4.5.x through 4.9.x allowing attackers (who control a stub domain kernel or tool stack) to cause a denial of service (host OS crash) because of a missing comparison (of range start to range end) within the DMOP map/unmap implementation.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-15592

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 HVM guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because self-linear shadow mappings are mishandled for translated guests.

    Published: 12 Oct 2017
    6.5
    Medium

    CVE-2017-15593

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (memory leak) because reference counts are mishandled.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-15594

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 SVM PV guest OS users to cause a denial of service (hypervisor crash) or gain privileges because IDT settings are mishandled during CPU hotplugging.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-15595

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-5123

    Last Modified: 21 Nov 2024

    Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.

    Published: 12 Oct 2017
    9.8
    Critical

    CVE-2017-12629

    Last Modified: 20 Apr 2025

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

    Published: 12 Oct 2017
    8.8
    High

    CVE-2017-15590

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x allowing x86 guest OS users to cause a denial of service (hypervisor crash) or possibly gain privileges because MSI mapping was mishandled.

    Published: 12 Oct 2017
    5.5
    Medium

    CVE-2017-18267

    Last Modified: 21 Nov 2024

    The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops.

    Published: 12 Oct 2017
    9.8
    Critical

    CVE-2017-5791

    Last Modified: 20 Apr 2025

    The doFilter method in UrlAccessController in HPE Intelligent Management Center (iMC) PLAT 7.2 E0403P06 allows remote bypass of authentication via unspecified strings in a URI.

    Published: 11 Oct 2017
    9.8
    Critical

    CVE-2017-5789

    Last Modified: 20 Apr 2025

    HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote attackers to execute arbitrary code via unspecified vectors. At least in LoadRunner, this is a libxdrutil.dll mxdr_string heap-based buffer overflow.

    Published: 11 Oct 2017
    9.8
    Critical

    CVE-2017-14003

    Last Modified: 20 Apr 2025

    An Authentication Bypass by Spoofing issue was discovered in LAVA Ether-Serial Link (ESL) running firmware versions 6.01.00/29.03.2007 and prior versions. An improper authentication vulnerability has been identified, which, if exploited, would allow an attacker with the same IP address to bypass authentication by accessing a specific uniform resource locator.

    Published: 11 Oct 2017
    7.4
    High

    CVE-2017-8025

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by an arbitrary file upload vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability to upload malicious files via attachments to arbitrary paths on the web server.

    Published: 11 Oct 2017
    4.3
    Medium

    CVE-2017-14369

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by a privilege escalation vulnerability. A low privileged RSA Archer user may potentially exploit this vulnerability to elevate their privileges and export certain application records.

    Published: 11 Oct 2017
    5.4
    Medium

    CVE-2017-8016

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Questionnaire ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

    Published: 11 Oct 2017
    5.4
    Medium

    CVE-2017-14370

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by stored cross-site scripting via the Source Asset ID field. An authenticated attacker may potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

    Published: 11 Oct 2017
    6.1
    Medium

    CVE-2017-14371

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting via the request URL. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

    Published: 11 Oct 2017
    6.1
    Medium

    CVE-2017-14372

    Last Modified: 20 Apr 2025

    RSA Archer GRC Platform prior to 6.2.0.5 is affected by reflected cross-site scripting vulnerabilities via certain RSA Archer Help pages. Attackers could potentially exploit this to execute arbitrary HTML in the user's browser session in the context of the affected RSA Archer application.

    Published: 11 Oct 2017
    6.1
    Medium

    CVE-2017-8017

    Last Modified: 20 Apr 2025

    EMC Network Configuration Manager (NCM) 9.3.x, 9.4.0.x, 9.4.1.x, and 9.4.2.x is affected by a reflected cross-site scripting Vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15241

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000000929f5."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15248

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x0000000000063ca6."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15255

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x00000000001601b0."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15262

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x0000000000048d0c."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15242

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x0000000000031abe."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15243

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x00000000000568a4."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15245

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlGetGlobalState+0x0000000000057b76."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15249

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlGetGlobalState+0x00000000000668d6."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15256

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x0000000000019fc8."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15263

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x00000000000166c4."

    Published: 11 Oct 2017
    5.4
    Medium

    CVE-2017-14587

    Last Modified: 20 Apr 2025

    The administration user deletion resource in Atlassian Fisheye and Crucible before version 4.4.2 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the uname parameter.

    Published: 11 Oct 2017
    6.1
    Medium

    CVE-2017-14588

    Last Modified: 20 Apr 2025

    Various resources in Atlassian Fisheye and Crucible before version 4.4.2 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the dialog parameter.

    Published: 11 Oct 2017
    Unknown

    CVE-2017-15083

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1642. Reason: This candidate is a reservation duplicate of CVE-2009-1642.2. Notes: All CVE users should reference CVE-2009-1642 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15239

    Last Modified: 20 Apr 2025

    IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000040db4."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15240

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access Violation starting at PDF!xmlParserInputRead+0x0000000000132cef."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15244

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to an "Error Code (0xe06d7363) starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15246

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "Read Access Violation on Block Data Move starting at PDF!xmlListWalk+0x000000000001515b."

    Published: 11 Oct 2017
    7.8
    High

    CVE-2017-15247

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x00000000001168a1."

    Published: 11 Oct 2017