CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-14081

    Last Modified: 20 Apr 2025

    Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

    Published: 22 Sept 2017
    8.8
    High

    CVE-2017-11395

    Last Modified: 20 Apr 2025

    Command injection vulnerability in Trend Micro Smart Protection Server (Standalone) 3.1 and 3.2 server administration UI allows attackers with authenticated access to execute arbitrary code on vulnerable installations.

    Published: 22 Sept 2017
    7.2
    High

    CVE-2017-11396

    Last Modified: 20 Apr 2025

    Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-14078

    Last Modified: 20 Apr 2025

    SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

    Published: 22 Sept 2017
    8.8
    High

    CVE-2017-14079

    Last Modified: 20 Apr 2025

    Unrestricted file uploads in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-14080

    Last Modified: 20 Apr 2025

    Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.

    Published: 22 Sept 2017
    6.7
    Medium

    CVE-2017-3763

    Last Modified: 20 Apr 2025

    An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA versions earlier than 1.3.2.

    Published: 22 Sept 2017
    8.8
    High

    CVE-2017-3770

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functionality to execute privileged commands within the underlying LXCA operating system.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-9393

    Last Modified: 20 Apr 2025

    CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14692

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllGetClassObject+0x000000000000653b."

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14693

    Last Modified: 20 Apr 2025

    IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613."

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14688

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Read Access Violation starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d917."

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14689

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUDjVuFile!DllUnregisterServer+0x000000000000328e."

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14690

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x00000000000064e7."

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14691

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_773a0000!RtlAddAccessAllowedAce+0x000000000000027a."

    Published: 22 Sept 2017
    6.5
    Medium

    CVE-2017-14653

    Last Modified: 20 Apr 2025

    member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-14636

    Last Modified: 20 Apr 2025

    Because of an integer overflow in sam2p 0.49.3, a loop executes 0xffffffff times, ending with an invalid read of size 1 in the Image::Indexed::sortPal function in image.cpp. However, this also causes memory corruption because of an attempted write to the invalid d[0xfffffffe] array element.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-14637

    Last Modified: 20 Apr 2025

    In sam2p 0.49.3, there is an invalid read of size 2 in the parse_rgb function in in_xpm.cpp. However, this can also cause a write to an illegal address.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14686

    Last Modified: 20 Apr 2025

    Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14685

    Last Modified: 20 Apr 2025

    Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14687

    Last Modified: 20 Apr 2025

    Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons.

    Published: 22 Sept 2017
    8.8
    High

    CVE-2017-8007

    Last Modified: 20 Apr 2025

    In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnerability to access unauthorized information, and modify or delete data, by supplying specially crafted strings in input parameters of the web service call.

    Published: 22 Sept 2017
    7.4
    High

    CVE-2017-8012

    Last Modified: 20 Apr 2025

    In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Java Management Extensions (JMX) protocol used to communicate between components in the Alerting and/or Compliance components can be leveraged to create a denial of service (DoS) condition. Attackers with knowledge of JMX agent user credentials could potentially exploit this vulnerability to create arbitrary files on the affected system and create a DoS condition by leveraging inherent JMX protocol capabilities.

    Published: 22 Sept 2017
    6.6
    Medium

    CVE-2017-16529

    Last Modified: 20 Apr 2025

    The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 22 Sept 2017
    9.8
    Critical

    CVE-2017-16844

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-14864

    Last Modified: 20 Apr 2025

    An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Sept 2017
    7.5
    High

    CVE-2017-15268

    Last Modified: 20 Apr 2025

    Qemu through 2.10.0 allows remote attackers to cause a memory leak by triggering slow data-channel read operations, related to io/channel-websock.c.

    Published: 22 Sept 2017
    6.6
    Medium

    CVE-2017-16530

    Last Modified: 20 Apr 2025

    The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device, related to drivers/usb/storage/uas-detect.h and drivers/usb/storage/uas.c.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-14863

    Last Modified: 20 Apr 2025

    A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-15024

    Last Modified: 20 Apr 2025

    find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-15025

    Last Modified: 20 Apr 2025

    decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file.

    Published: 22 Sept 2017
    7.8
    High

    CVE-2017-14729

    Last Modified: 20 Apr 2025

    The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, do not ensure a unique PLT entry for a symbol, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.

    Published: 22 Sept 2017
    5.5
    Medium

    CVE-2017-14681

    Last Modified: 20 Apr 2025

    The daemon in P3Scan 3.0_rc1 and earlier creates a p3scan.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for p3scan.pid modification before a root script executes a "kill `cat /pathname/p3scan.pid`" command, as demonstrated by etc/init.d/p3scan.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2017-14680

    Last Modified: 20 Apr 2025

    ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2017-9281

    Last Modified: 20 Apr 2025

    An integer overflow (CWE-190) potentially causing an out-of-bounds read (CWE-125) vulnerability in Micro Focus VisiBroker 8.5 can lead to a denial of service.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-9282

    Last Modified: 20 Apr 2025

    An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-9283

    Last Modified: 20 Apr 2025

    An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-12170

    Last Modified: 20 Apr 2025

    Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-14652

    Last Modified: 20 Apr 2025

    SQL Injection vulnerability in mobiquo/lib/classTTForum.php in the Tapatalk plugin before 4.5.8 for MyBB allows an unauthenticated remote attacker to inject arbitrary SQL commands via an XML-RPC encoded document sent as part of the user registration process.

    Published: 21 Sept 2017
    4.8
    Medium

    CVE-2017-14651

    Last Modified: 20 Apr 2025

    WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-14639

    Last Modified: 20 Apr 2025

    AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buffer underflow and out-of-bounds write, leading to denial of service (application crash) or possibly unspecified other impact.

    Published: 21 Sept 2017
    8.1
    High

    CVE-2017-14650

    Last Modified: 20 Apr 2025

    A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable through any Horde application, because the code path to the vulnerability is not used by any Horde code. Custom applications using the Horde_Image library might be affected. This vulnerability affects all versions of Horde_Image from 2.0.0 to 2.5.1, and is fixed in 2.5.2. The problem is missing input validation of the index field in _raw() during construction of an ImageMagick command line.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14638

    Last Modified: 20 Apr 2025

    AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer dereference, segmentation fault, and application crash in AP4_Atom::SetType in Core/Ap4Atom.h.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14641

    Last Modified: 20 Apr 2025

    A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14643

    Last Modified: 20 Apr 2025

    The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over-read and application crash in AP4_BytesToUInt32BE in Core/Ap4Utils.h.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-14644

    Last Modified: 20 Apr 2025

    A heap-based buffer overflow was discovered in the AP4_HdlrAtom class in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14645

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability causes an application crash, which leads to remote denial of service.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2017-14646

    Last Modified: 20 Apr 2025

    The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read and application crash in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-14649

    Last Modified: 20 Apr 2025

    ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14640

    Last Modified: 20 Apr 2025

    A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

    Published: 21 Sept 2017