CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-15203

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15204

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15205

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15206

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15209

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15210

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can see thumbnails of pictures from a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15211

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of another user.

    Published: 10 Oct 2017
    4.3
    Medium

    CVE-2017-15212

    Last Modified: 20 Apr 2025

    In Kanboard before 1.0.47, by altering form data, an authenticated user can at least see the names of tags of a private project of another user.

    Published: 10 Oct 2017
    5.4
    Medium

    CVE-2017-15213

    Last Modified: 20 Apr 2025

    Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-0903

    Last Modified: 20 Apr 2025

    RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

    Published: 10 Oct 2017
    6.5
    Medium

    CVE-2017-16818

    Last Modified: 20 Apr 2025

    RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12176

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12177

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12180

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12183

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    7.5
    High

    CVE-2017-15192

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.

    Published: 10 Oct 2017
    8.8
    High

    CVE-2017-2888

    Last Modified: 20 Apr 2025

    An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.

    Published: 10 Oct 2017
    7.5
    High

    CVE-2017-15193

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12179

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12181

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12182

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12185

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12186

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12187

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    7.5
    High

    CVE-2017-15189

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 to 2.4.1, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by adding decrements.

    Published: 10 Oct 2017
    7.5
    High

    CVE-2017-15190

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 to 2.4.1, the RTSP dissector could crash. This was addressed in epan/dissectors/packet-rtsp.c by correcting the scope of a variable.

    Published: 10 Oct 2017
    7.5
    High

    CVE-2017-15191

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.

    Published: 10 Oct 2017
    6.6
    Medium

    CVE-2017-16527

    Last Modified: 20 Apr 2025

    sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 10 Oct 2017
    6.6
    Medium

    CVE-2017-16647

    Last Modified: 20 Apr 2025

    drivers/net/usb/asix_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12178

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2017-12184

    Last Modified: 29 Aug 2025

    xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X server to crash or possibly execute arbitrary code.

    Published: 10 Oct 2017
    7.8
    High

    CVE-2017-12188

    Last Modified: 20 Apr 2025

    arch/x86/kvm/mmu.c in the Linux kernel through 4.13.5, when nested virtualisation is used, does not properly traverse guest pagetable entries to resolve a guest virtual address, which allows L1 guest OS users to execute arbitrary code on the host OS or cause a denial of service (incorrect index during page walking, and host OS crash), aka an "MMU potential stack buffer overrun."

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2018-6485

    Last Modified: 21 Nov 2024

    An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption.

    Published: 10 Oct 2017
    9.8
    Critical

    CVE-2014-0030

    Last Modified: 20 Apr 2025

    The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

    Published: 9 Oct 2017
    7.1
    High

    CVE-2015-7842

    Last Modified: 20 Apr 2025

    Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 allow remote authenticated operators to change server information by leveraging failure to verify user permissions.

    Published: 9 Oct 2017
    6.5
    Medium

    CVE-2017-14614

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the Visor GUI Console in GridGain before 1.7.16, 1.8.x before 1.8.12, 1.9.x before 1.9.7, and 8.x before 8.1.5 allows remote authenticated users to read arbitrary files on remote cluster nodes via a crafted path.

    Published: 9 Oct 2017
    9.8
    Critical

    CVE-2017-14980

    Last Modified: 20 Apr 2025

    Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

    Published: 9 Oct 2017
    7.5
    High

    CVE-2017-14603

    Last Modified: 20 Apr 2025

    In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cert6, insufficient RTCP packet validation could allow reading stale buffer contents and when combined with the "nat" and "symmetric_rtp" options allow redirecting where Asterisk sends the next RTCP report.

    Published: 9 Oct 2017
    5
    Medium

    CVE-2017-15185

    Last Modified: 20 Apr 2025

    plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 9 Oct 2017
    5.5
    Medium

    CVE-2017-14971

    Last Modified: 20 Apr 2025

    Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scenario, the attacker provides an Excel spreadsheet, and the attacker-controller server receives the victim's NetNTLMv2 hash.

    Published: 9 Oct 2017
    7.5
    High

    CVE-2017-14972

    Last Modified: 20 Apr 2025

    InFocus Mondopad 2.2.08 is vulnerable to authentication bypass when accessing uploaded files by entering Control-Alt-Delete, and then using Task Manager to reach a file.

    Published: 9 Oct 2017
    5.4
    Medium

    CVE-2017-14973

    Last Modified: 20 Apr 2025

    IDenticard Two-Reader Controller Configuration Manager 1.18.8 (396) is vulnerable to Stored Cross-Site Scripting (XSS) via the notes field in /~user_handler?file=logged_in.shtm (aka the edit user page).

    Published: 9 Oct 2017
    8.8
    High

    CVE-2017-15281

    Last Modified: 20 Apr 2025

    ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised value(s)."

    Published: 9 Oct 2017
    7.8
    High

    CVE-2014-8184

    Last Modified: 21 Nov 2024

    A vulnerability was found in liblouis, versions 2.5.x before 2.5.4. A stack-based buffer overflow was found in findTable() in liblouis. An attacker could create a malicious file that would cause applications that use liblouis (such as Orca) to crash, or potentially execute arbitrary code when opened.

    Published: 9 Oct 2017
    6.6
    Medium

    CVE-2017-16537

    Last Modified: 20 Apr 2025

    The imon_probe function in drivers/media/rc/imon.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 9 Oct 2017
    5.5
    Medium

    CVE-2017-1000255

    Last Modified: 20 Apr 2025

    On Linux running on PowerPC hardware (Power8 or later) a user process can craft a signal frame and then do a sigreturn so that the kernel will take an exception (interrupt), and use the r1 value *from the signal frame* as the kernel stack pointer. As part of the exception entry the content of the signal frame is written to the kernel stack, allowing an attacker to overwrite arbitrary locations with arbitrary values. The exception handling does produce an oops, and a panic if panic_on_oops=1, but only after kernel memory has been over written. This flaw was introduced in commit: "5d176f751ee3 (powerpc: tm: Enable transactional memory (TM) lazily for userspace)" which was merged upstream into v4.9-rc1. Please note that kernels built with CONFIG_PPC_TRANSACTIONAL_MEM=n are not vulnerable.

    Published: 9 Oct 2017
    4.8
    Medium

    CVE-2015-2148

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 6 Oct 2017
    8.8
    High

    CVE-2015-2673

    Last Modified: 20 Apr 2025

    The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyCart plugin 1.1.30 through 3.0.20 for WordPress allow remote attackers to gain administrator privileges and execute arbitrary code via the option_name and option_value parameters.

    Published: 6 Oct 2017
    5.9
    Medium

    CVE-2015-1828

    Last Modified: 20 Apr 2025

    The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.

    Published: 6 Oct 2017
    8
    High

    CVE-2015-2142

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that cause an unspecified impact via the id parameter to project.php, (2) hijack the authentication of users for requests that cause an unspecified impact via the group_id parameter to group.php, (3) hijack the authentication of users for requests that delete statuses via the status_id parameter to status.php, (4) hijack the authentication of users for requests that delete severities via the severity_id parameter to severity.php, (5) hijack the authentication of users for requests that cause an unspecified impact via the priority_id parameter to priority.php, (6) hijack the authentication of users for requests that delete the operating system via the os_id parameter to os.php, (7) hijack the authentication of users for requests that delete databases via the database_id parameter to database.php, or (8) hijack the authentication of users for requests that delete sites via the site_id parameter to sites.php.

    Published: 6 Oct 2017