CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-12820

    Last Modified: 20 Apr 2025

    Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.

    Published: 3 Oct 2017
    6.5
    Medium

    CVE-2017-14994

    Last Modified: 20 Apr 2025

    ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.

    Published: 3 Oct 2017
    6.5
    Medium

    CVE-2017-14997

    Last Modified: 20 Apr 2025

    GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.

    Published: 3 Oct 2017
    6.1
    Medium

    CVE-2017-8047

    Last Modified: 20 Apr 2025

    In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

    Published: 3 Oct 2017
    7.8
    High

    CVE-2017-8048

    Last Modified: 20 Apr 2025

    In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

    Published: 3 Oct 2017
    6.1
    Medium

    CVE-2017-14995

    Last Modified: 20 Apr 2025

    The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS.

    Published: 3 Oct 2017
    6.5
    Medium

    CVE-2017-9792

    Last Modified: 20 Apr 2025

    In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by altering the table properties to make it "external" and then changing the underlying table mapping to point to other Kudu tables. This violates and works around the authorization requirement that creating a Kudu external table via Impala requires an "ALL" privilege at the server scope. This privilege requirement for "CREATE" commands is enforced to precisely avoid this scenario where a malicious user can change the underlying Kudu table mapping. The fix is to enforce the same privilege requirement for "ALTER" commands that would make existing non-external Kudu tables external.

    Published: 3 Oct 2017
    5.3
    Medium

    CVE-2017-15906

    Last Modified: 28 May 2026

    The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

    Published: 3 Oct 2017
    6.5
    Medium

    CVE-2017-14992

    Last Modified: 20 Apr 2025

    Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09.0, and earlier allows a remote attacker to cause a Denial of Service via a crafted image layer payload, aka gzip bombing.

    Published: 3 Oct 2017
    4.3
    Medium

    CVE-2017-12173

    Last Modified: 21 Nov 2024

    It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve it.

    Published: 3 Oct 2017
    9.8
    Critical

    CVE-2017-12639

    Last Modified: 20 Apr 2025

    Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETRE or ETCTERARED.

    Published: 2 Oct 2017
    5.5
    Medium

    CVE-2017-14771

    Last Modified: 20 Apr 2025

    Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.

    Published: 2 Oct 2017
    3.3
    Low

    CVE-2017-14772

    Last Modified: 20 Apr 2025

    Skybox Manager Client Application is prone to information disclosure via a username enumeration attack. A local unauthenticated attacker could exploit the flaw to obtain valid usernames, by analyzing error messages upon valid and invalid account login attempts.

    Published: 2 Oct 2017
    7.8
    High

    CVE-2017-14773

    Last Modified: 20 Apr 2025

    Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state. The vulnerability can only be exploited by a local authenticated attacker.

    Published: 2 Oct 2017
    9.8
    Critical

    CVE-2017-11496

    Last Modified: 20 Apr 2025

    Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via malformed ASN.1 streams in V2C and similar input files.

    Published: 2 Oct 2017
    9.8
    Critical

    CVE-2017-11497

    Last Modified: 20 Apr 2025

    Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters.

    Published: 2 Oct 2017
    7.5
    High

    CVE-2017-11498

    Last Modified: 20 Apr 2025

    Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote process (a denial of service) via a language pack (ZIP file) with invalid HTML files.

    Published: 2 Oct 2017
    5.5
    Medium

    CVE-2017-14770

    Last Modified: 20 Apr 2025

    Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the password hashes in a debugger-pause state during the authentication process.

    Published: 2 Oct 2017
    8.8
    High

    CVE-2017-14848

    Last Modified: 20 Apr 2025

    WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.

    Published: 2 Oct 2017
    9.8
    Critical

    CVE-2017-12638

    Last Modified: 20 Apr 2025

    Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETBL or ETCETERABLUE.

    Published: 2 Oct 2017
    7.5
    High

    CVE-2017-1569

    Last Modified: 20 Apr 2025

    IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.

    Published: 2 Oct 2017
    8.8
    High

    CVE-2017-1311

    Last Modified: 20 Apr 2025

    IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 125719.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1324

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125975.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1334

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126242.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1335

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126243.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1345

    Last Modified: 20 Apr 2025

    IBM Insights Foundation for Energy 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126460.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1359

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126686.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1364

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126857.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1369

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126862.

    Published: 2 Oct 2017
    5.4
    Medium

    CVE-2017-1429

    Last Modified: 20 Apr 2025

    IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127587.

    Published: 2 Oct 2017
    7.8
    High

    CVE-2015-7358

    Last Modified: 20 Apr 2025

    The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted volume over an existing drive letter and gain privileges via an entry in the /GLOBAL?? directory.

    Published: 2 Oct 2017
    6.1
    Medium

    CVE-2015-7357

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the uDesign (aka U-Design) theme 2.3.0 before 2.7.10 for WordPress allows remote attackers to inject arbitrary web script or HTML via a fragment identifier, as demonstrated by #<svg onload=alert(1)>.

    Published: 2 Oct 2017
    7.8
    High

    CVE-2015-7359

    Last Modified: 20 Apr 2025

    The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows local users to impersonate a user at SecurityIdentify level and gain access to other users' mounted encrypted volumes.

    Published: 2 Oct 2017
    8.8
    High

    CVE-2015-6576

    Last Modified: 20 Apr 2025

    Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.

    Published: 2 Oct 2017
    9.8
    Critical

    CVE-2015-7841

    Last Modified: 20 Apr 2025

    The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 allows remote attackers to bypass access restrictions and enter commands via unspecified parameters, as demonstrated by a "user creation command."

    Published: 2 Oct 2017
    6.7
    Medium

    CVE-2015-3321

    Last Modified: 20 Apr 2025

    Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain privileges via standard filesystem operations.

    Published: 2 Oct 2017
    7.8
    High

    CVE-2015-6971

    Last Modified: 20 Apr 2025

    Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.

    Published: 2 Oct 2017
    8.8
    High

    CVE-2015-7843

    Last Modified: 20 Apr 2025

    The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 does not limit the number of query attempts, which allows remote authenticated users to obtain credentials of higher-level users via a brute force attack.

    Published: 2 Oct 2017
    6.1
    Medium

    CVE-2015-7980

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "embedding a JavaScript library from an external source that was not reliable."

    Published: 2 Oct 2017
    7.2
    High

    CVE-2017-11321

    Last Modified: 20 Apr 2025

    The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admin' privileges via shell metacharacters in the less command.

    Published: 2 Oct 2017
    8.2
    High

    CVE-2017-11322

    Last Modified: 20 Apr 2025

    The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client.

    Published: 2 Oct 2017
    6.1
    Medium

    CVE-2017-14756

    Last Modified: 20 Apr 2025

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/Deployment (cat_id).

    Published: 2 Oct 2017
    8.8
    High

    CVE-2017-14757

    Last Modified: 20 Apr 2025

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

    Published: 2 Oct 2017
    8.8
    High

    CVE-2017-6090

    Last Modified: 20 Apr 2025

    Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.

    Published: 2 Oct 2017
    7.5
    High

    CVE-2017-14979

    Last Modified: 20 Apr 2025

    Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to read arbitrary files via modified pathnames in the s parameter to index.php, related to Lib/Admin/Action/TplAction.class.php and Lib/Admin/Common/function.php.

    Published: 2 Oct 2017
    9.8
    Critical

    CVE-2017-6089

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.

    Published: 2 Oct 2017
    6.1
    Medium

    CVE-2017-14755

    Last Modified: 20 Apr 2025

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Cross-Site Scripting: /xAdmin/html/XPressoDoc, parameter: categoryId.

    Published: 2 Oct 2017
    6.5
    Medium

    CVE-2017-14754

    Last Modified: 20 Apr 2025

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to Arbitrary File Read: /xAdmin/html/cm_datasource_group_xsd.jsp, parameter: xsd_datasource_schema_file filename. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

    Published: 2 Oct 2017
    6.5
    Medium

    CVE-2017-14990

    Last Modified: 20 Apr 2025

    WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability).

    Published: 2 Oct 2017
    8.8
    High

    CVE-2017-14758

    Last Modified: 20 Apr 2025

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

    Published: 2 Oct 2017