CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2015-3643

    Last Modified: 20 Apr 2025

    usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call check_polkit for the KVMTest method.

    Published: 27 Sept 2017
    7
    High

    CVE-2017-13676

    Last Modified: 20 Apr 2025

    Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application. A Norton Remove & Reinstall update, version 4.4.0.58, has been released which addresses the aforementioned vulnerability.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14763

    Last Modified: 20 Apr 2025

    In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-14760

    Last Modified: 20 Apr 2025

    SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14761

    Last Modified: 20 Apr 2025

    In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14765

    Last Modified: 20 Apr 2025

    In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.

    Published: 27 Sept 2017
    7.5
    High

    CVE-2017-14766

    Last Modified: 20 Apr 2025

    The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14767

    Last Modified: 20 Apr 2025

    The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other impact via a crafted sdp file.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14762

    Last Modified: 20 Apr 2025

    In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-14764

    Last Modified: 20 Apr 2025

    In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

    Published: 27 Sept 2017
    5.4
    Medium

    CVE-2017-14753

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the filter parameter to module/module_filters/index.php.

    Published: 27 Sept 2017
    5.5
    Medium

    CVE-2017-14988

    Last Modified: 20 Apr 2025

    Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file that is accessed with the ImfOpenInputFile function in IlmImf/ImfCRgbaFile.cpp. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid

    Published: 27 Sept 2017
    5.5
    Medium

    CVE-2017-15299

    Last Modified: 20 Apr 2025

    The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

    Published: 27 Sept 2017
    8.8
    High

    CVE-2017-11191

    Last Modified: 20 Apr 2025

    FreeIPA 4.x with API version 2.213 allows a remote authenticated users to bypass intended account-locking restrictions via an unlock action with an old session ID (for the same user account) that had been created for an earlier session. NOTE: Vendor states that issue does not exist in product and does not recognize this report as a valid security concern

    Published: 27 Sept 2017
    9.8
    Critical

    CVE-2017-12621

    Last Modified: 20 Apr 2025

    During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL. This could lead to XML External Entity (XXE) attacks in Apache Commons Jelly before 1.0.1.

    Published: 27 Sept 2017
    7.5
    High

    CVE-2017-14868

    Last Modified: 20 Apr 2025

    Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.

    Published: 27 Sept 2017
    5.5
    Medium

    CVE-2017-14934

    Last Modified: 20 Apr 2025

    process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure.

    Published: 27 Sept 2017
    7.5
    High

    CVE-2017-16136

    Last Modified: 21 Nov 2024

    method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

    Published: 27 Sept 2017
    6.1
    Medium

    CVE-2017-14751

    Last Modified: 20 Apr 2025

    The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field.

    Published: 26 Sept 2017
    7.8
    High

    CVE-2017-14749

    Last Modified: 20 Apr 2025

    JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

    Published: 26 Sept 2017
    5.4
    Medium

    CVE-2017-1530

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130409.

    Published: 26 Sept 2017
    8.1
    High

    CVE-2017-1527

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 130156.

    Published: 26 Sept 2017
    5.4
    Medium

    CVE-2017-1425

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 8.0.1.1 and 8.5.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127478.

    Published: 26 Sept 2017
    5.4
    Medium

    CVE-2017-1531

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 130410.

    Published: 26 Sept 2017
    8.8
    High

    CVE-2017-1539

    Last Modified: 20 Apr 2025

    IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to privilege escalation by not properly distinguishing internal group memberships from user registry group memberships. By manipulating LDAP group membership an attack might gain privileged access. IBM X-Force ID: 130807.

    Published: 26 Sept 2017
    5.3
    Medium

    CVE-2017-14748

    Last Modified: 20 Apr 2025

    Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific time during the initial loading of that match.

    Published: 26 Sept 2017
    6.1
    Medium

    CVE-2015-7391

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date parameter to lib/results/tcCreatedPerUserOnTestProject.php; the (3) containerType parameter to lib/testcases/containerEdit.php; the (4) filter_tc_id or (5) filter_testcase_name parameter to lib/testcases/listTestCases.php; the (6) useRecursion parameter to lib/testcases/tcImport.php; the (7) targetTestCase or (8) created_by parameter to lib/testcases/tcSearch.php; or the (9) HTTP Referer header to third_party/user_contribution/fakeRemoteExecServer/client4fakeXMLRPCTestRunner.php.

    Published: 26 Sept 2017
    9.8
    Critical

    CVE-2015-7670

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.

    Published: 26 Sept 2017
    9.8
    Critical

    CVE-2015-7390

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.

    Published: 26 Sept 2017
    5.9
    Medium

    CVE-2015-0874

    Last Modified: 20 Apr 2025

    Smartphone Passbook 1.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information from encrypted communications via a crafted certificate.

    Published: 26 Sept 2017
    4.3
    Medium

    CVE-2015-5069

    Last Modified: 20 Apr 2025

    The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.

    Published: 26 Sept 2017
    8
    High

    CVE-2017-13129

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

    Published: 26 Sept 2017
    7.2
    High

    CVE-2017-14602

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e before build 60.7010.e, 11.0 before build 70.16, 11.1 before build 55.13, and 12.0 before build 53.13 (except for build 41.24) that, if exploited, could allow an attacker with access to the NetScaler management interface to gain administrative access to the appliance.

    Published: 26 Sept 2017
    3.1
    Low

    CVE-2015-5070

    Last Modified: 20 Apr 2025

    The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.

    Published: 26 Sept 2017
    8.8
    High

    CVE-2017-14704

    Last Modified: 20 Apr 2025

    Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.

    Published: 26 Sept 2017
    9.8
    Critical

    CVE-2017-14703

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.

    Published: 26 Sept 2017
    8.1
    High

    CVE-2017-14743

    Last Modified: 20 Apr 2025

    Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.

    Published: 26 Sept 2017
    6.1
    Medium

    CVE-2017-14744

    Last Modified: 20 Apr 2025

    UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.

    Published: 26 Sept 2017
    8.8
    High

    CVE-2017-14001

    Last Modified: 20 Apr 2025

    An Improper Neutralization of Special Elements used in an OS Command issue was discovered in Digium Asterisk GUI 2.1.0 and prior. An OS command injection vulnerability has been identified that may allow the execution of arbitrary code on the system through the inclusion of OS commands in the URL request of the program.

    Published: 26 Sept 2017
    5.5
    Medium

    CVE-2017-14737

    Last Modified: 20 Apr 2025

    A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array is indexed with bits derived from a secret key.

    Published: 26 Sept 2017
    5.5
    Medium

    CVE-2017-14933

    Last Modified: 20 Apr 2025

    read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.

    Published: 26 Sept 2017
    7.8
    High

    CVE-2017-1000253

    Last Modified: 21 Apr 2026

    Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.

    Published: 26 Sept 2017
    6.6
    Medium

    CVE-2017-16538

    Last Modified: 20 Apr 2025

    drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm-start check and incorrect attach timing (dm04_lme2510_frontend_attach versus dm04_lme2510_tuner).

    Published: 26 Sept 2017
    9.8
    Critical

    CVE-2017-14695

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12791.

    Published: 26 Sept 2017
    8.8
    High

    CVE-2017-1000450

    Last Modified: 21 Nov 2024

    In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

    Published: 26 Sept 2017
    6.5
    Medium

    CVE-2017-2582

    Last Modified: 21 Nov 2024

    It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which could be obtained in the "InResponseTo" field in the response.

    Published: 26 Sept 2017
    7
    High

    CVE-2017-7536

    Last Modified: 21 Nov 2024

    In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().

    Published: 26 Sept 2017
    7.5
    High

    CVE-2017-14696

    Last Modified: 20 Apr 2025

    SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a crafted authentication request.

    Published: 26 Sept 2017
    8.8
    High

    CVE-2017-14867

    Last Modified: 20 Apr 2025

    Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

    Published: 26 Sept 2017
    5.5
    Medium

    CVE-2017-15225

    Last Modified: 20 Apr 2025

    _bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file.

    Published: 26 Sept 2017