CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-12229

    Last Modified: 20 Apr 2025

    A vulnerability in the REST API of the web-based user interface (web UI) of Cisco IOS XE 3.1 through 16.5 could allow an unauthenticated, remote attacker to bypass authentication to the REST API of the web UI of the affected software. The vulnerability is due to insufficient input validation for the REST API of the affected software. An attacker could exploit this vulnerability by sending a malicious API request to an affected device. A successful exploit could allow the attacker to bypass authentication and gain access to the web UI of the affected software. This vulnerability affects Cisco devices that are running a vulnerable release of Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuz46036.

    Published: 28 Sept 2017
    9.8
    Critical

    CVE-2017-7793

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    7.8
    High

    CVE-2018-9568

    Last Modified: 21 Nov 2024

    In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References: Upstream kernel.

    Published: 28 Sept 2017
    5.3
    Medium

    CVE-2017-7825

    Last Modified: 25 Nov 2025

    Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    9.8
    Critical

    CVE-2017-7819

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    6.6
    Medium

    CVE-2017-16533

    Last Modified: 20 Apr 2025

    The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 28 Sept 2017
    6.5
    Medium

    CVE-2017-17046

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, because disjoint blocks, and physical addresses that do not start at zero, are mishandled.

    Published: 28 Sept 2017
    8.8
    High

    CVE-2017-15565

    Last Modified: 20 Apr 2025

    In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document.

    Published: 28 Sept 2017
    6.1
    Medium

    CVE-2017-11479

    Last Modified: 20 Apr 2025

    Kibana versions prior to 5.6.1 had a cross-site scripting (XSS) vulnerability in Timelion that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

    Published: 28 Sept 2017
    7.5
    High

    CVE-2017-14849

    Last Modified: 20 Apr 2025

    Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

    Published: 28 Sept 2017
    7.5
    High

    CVE-2017-7805

    Last Modified: 21 Nov 2024

    During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    5.4
    Medium

    CVE-2017-7823

    Last Modified: 25 Nov 2025

    The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    9.8
    Critical

    CVE-2017-7810

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    9.8
    Critical

    CVE-2017-7824

    Last Modified: 25 Nov 2025

    A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    9.8
    Critical

    CVE-2017-7818

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    7.8
    High

    CVE-2017-7814

    Last Modified: 25 Nov 2025

    File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

    Published: 28 Sept 2017
    8.8
    High

    CVE-2017-14840

    Last Modified: 20 Apr 2025

    TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14838

    Last Modified: 20 Apr 2025

    TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14839

    Last Modified: 20 Apr 2025

    TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14843

    Last Modified: 20 Apr 2025

    Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14844

    Last Modified: 20 Apr 2025

    Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14845

    Last Modified: 20 Apr 2025

    Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14846

    Last Modified: 20 Apr 2025

    Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14847

    Last Modified: 20 Apr 2025

    Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    6.5
    Medium

    CVE-2017-14841

    Last Modified: 20 Apr 2025

    Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14842

    Last Modified: 20 Apr 2025

    Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.

    Published: 27 Sept 2017
    5.9
    Medium

    CVE-2014-9686

    Last Modified: 20 Apr 2025

    The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7428.

    Published: 27 Sept 2017
    5.5
    Medium

    CVE-2015-1526

    Last Modified: 20 Apr 2025

    The media_server component in Android allows remote attackers to cause a denial of service via a crafted application.

    Published: 27 Sept 2017
    7.8
    High

    CVE-2015-1537

    Last Modified: 20 Apr 2025

    Integer overflow in IHDCP.cpp in the media_server component in Android allows remote attackers to execute arbitrary code via a crafted application.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2015-7349

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the sample feedback.inc file in VASCO DIGIPASS authentication plug-in for Citrix Web Interface allows remote attackers to inject arbitrary web script or HTML via the failmessage parameter.

    Published: 27 Sept 2017
    5.9
    Medium

    CVE-2015-7256

    Last Modified: 20 Apr 2025

    ZyXEL NWA1100-N, NWA1100-NH, NWA1121-NI, NWA1123-AC, and NWA1123-NI access points; P-660HN-51, P-663HN-51, VMG1312-B10A, VMG1312-B30A, VMG1312-B30B, VMG4380-B10A, VMG8324-B10A, VMG8924-B10A, VMG8924-B30A, and VSG1435-B101 DSL CPEs; PMG5318-B20A GPONs; SBG3300-N000, SBG3300-NB00, and SBG3500-N000 small business gateways; GS1900-8 and GS1900-24 switches; and C1000Z, Q1000, FR1000Z, and P8702N project models use non-unique X.509 certificates and SSH host keys.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2015-8249

    Last Modified: 20 Apr 2025

    The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-11121

    Last Modified: 20 Apr 2025

    On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, properly crafted malicious over-the-air Fast Transition frames can potentially trigger internal Wi-Fi firmware heap and/or stack overflows, leading to denial of service or other effects, aka B-V2017061205.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-12814

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the CPerlHost::Add method in win32/perlhost.h in Perl before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 on Windows allows attackers to execute arbitrary code via a long environment variable.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-1407

    Last Modified: 20 Apr 2025

    IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14524

    Last Modified: 20 Apr 2025

    Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14526

    Last Modified: 20 Apr 2025

    Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

    Published: 27 Sept 2017
    7.5
    High

    CVE-2017-1577

    Last Modified: 20 Apr 2025

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 132117.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14795

    Last Modified: 20 Apr 2025

    The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with hls_pcm_sample in hevc.c in libavcodec in FFmpeg and put_pcm_var in hevcdsp_template.c in libavcodec in FFmpeg.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14796

    Last Modified: 20 Apr 2025

    The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with copy_CTB_to_hv in hevc_filter.c in libavcodec in FFmpeg and sao_filter_CTB in hevc_filter.c in libavcodec in FFmpeg.

    Published: 27 Sept 2017
    5.4
    Medium

    CVE-2015-5613

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in October CMS build 271 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving a file title, a different vulnerability than CVE-2015-5612.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-11120

    Last Modified: 20 Apr 2025

    On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor report frame to trigger an internal buffer overflow in the Wi-Fi firmware, aka B-V2017061204.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14527

    Last Modified: 20 Apr 2025

    Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14622

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter or (2) kbAction parameter in the kbAmz page to wp-admin/admin.php.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-1591

    Last Modified: 20 Apr 2025

    IBM WebSphere DataPower Appliances 7.0.0 through 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132368.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14525

    Last Modified: 20 Apr 2025

    Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

    Published: 27 Sept 2017
    8.6
    High

    CVE-2017-1483

    Last Modified: 20 Apr 2025

    IBM Security Identity Manager Adapters 6.0 and 7.0 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 128621.

    Published: 27 Sept 2017
    5.9
    Medium

    CVE-2017-14775

    Last Modified: 20 Apr 2025

    Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

    Published: 27 Sept 2017
    7.5
    High

    CVE-2017-2551

    Last Modified: 20 Apr 2025

    Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-10932

    Last Modified: 20 Apr 2025

    All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.

    Published: 27 Sept 2017