CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-14642

    Last Modified: 20 Apr 2025

    A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and application crash in AP4_StdcFileByteStream::ReadPartial in System/StdC/Ap4StdCFileByteStream.cpp, which leads to remote denial of service.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-14647

    Last Modified: 20 Apr 2025

    A heap-based buffer overflow was discovered in AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-14648

    Last Modified: 20 Apr 2025

    A global buffer overflow was discovered in the iteration_loop function in loop.c in BladeEnc version 0.94.2. The vulnerability causes an out-of-bounds write, which leads to remote denial of service or possibly code execution.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2015-1187

    Last Modified: 21 Apr 2026

    The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.

    Published: 21 Sept 2017
    5.4
    Medium

    CVE-2017-14321

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2015-3887

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in ProxyChains-NG before 4.9 allows local users to gain privileges via a Trojan horse libproxychains4.so library in the current working directory, which is referenced in the LD_PRELOAD path.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-12928

    Last Modified: 20 Apr 2025

    A hard-coded password of tecn0visi0n for the dlxuser account in TecnoVISION DLX Spot Player4 (all known versions) allows remote attackers to log in via SSH and escalate privileges to root access with the same credentials.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-12929

    Last Modified: 20 Apr 2025

    Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-12930

    Last Modified: 20 Apr 2025

    SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.

    Published: 21 Sept 2017
    8
    High

    CVE-2017-14320

    Last Modified: 20 Apr 2025

    Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-10999

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, concurrent calls into ioctl RMNET_IOCTL_ADD_MUX_CHANNEL in ipa wan driver may lead to memory corruption due to missing locks.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-11041

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-10998

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in audio_aio_ion_lookup_vaddr, the buffer length, which is user input, ends up being used to validate if the buffer is fully within the valid region. If the buffer length is large enough then the address + length operation could overflow and produce a result far below the valid region.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-11040

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, when reading from sysfs nodes, one can read more information than it is allowed to.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-8277

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in the function msm_dba_register_client, if the client registers failed, it would be freed. However the client was not removed from list. Use-after-free would occur when traversing the list next time.

    Published: 21 Sept 2017
    4.7
    Medium

    CVE-2017-9676

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, potential use after free scenarios and race conditions can occur when accessing global static variables without using a lock.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-9677

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in function msm_compr_ioctl_shared, variable "ddp->params_length" could be accessed and modified by multiple threads, while it is not protected with locks. If one thread is running, while another thread is setting data, race conditions will happen. If "ddp->params_length" is set to a big number, a buffer overflow will occur.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-9724

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, user-level permissions can be used to gain access to kernel memory, specifically the ION cache maintenance code is writing to a user supplied address.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-10997

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, using a debugfs node, a write to a PCIe register can cause corruption of kernel memory.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-10996

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, out of bounds access is possible in c_show(), due to compat_hwcap_str[] not being NULL-terminated. This error is not fatal, however the device might crash/reboot with memory violation/out of bounds access.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-11000

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in an ISP Camera kernel driver function, an incorrect bounds check may potentially lead to an out-of-bounds write.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-11001

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the length of the MAC address is not checked which may cause out of bounds read.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-11002

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-8247

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, if there is more than one thread doing the device open operation, the device may be opened more than once. This would lead to get_pid being called more than once, however put_pid being called only once in function "msm_close".

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-8250

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, user controlled variables "nr_cmds" and "nr_bos" number are passed across functions without any check. An integer overflow to buffer overflow (with a smaller buffer allocated) may occur when they are too large or negative.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-8251

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in functions msm_isp_check_stream_cfg_cmd & msm_isp_stats_update_cgc_override, 'stream_cfg_cmd->num_streams' is not checked, and could overflow the array stream_cfg_cmd->stream_handle.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-8278

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, while reading audio data from an unspecified driver, a buffer overflow or integer overflow could occur.

    Published: 21 Sept 2017
    7
    High

    CVE-2017-8280

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context switch.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-9720

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, due to an off-by-one error in a camera driver, an out-of-bounds read/write can occur.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2015-0276

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.

    Published: 21 Sept 2017
    6.1
    Medium

    CVE-2015-3296

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.

    Published: 21 Sept 2017
    6.1
    Medium

    CVE-2015-4706

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in IPython 3.x before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/contents path.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2015-8559

    Last Modified: 20 Apr 2025

    The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-14635

    Last Modified: 20 Apr 2025

    In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-14628

    Last Modified: 20 Apr 2025

    In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2017-14629

    Last Modified: 20 Apr 2025

    In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array element.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-14630

    Last Modified: 20 Apr 2025

    In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.

    Published: 21 Sept 2017
    9.8
    Critical

    CVE-2017-14631

    Last Modified: 20 Apr 2025

    In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-12214

    Last Modified: 20 Apr 2025

    A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voice Portal (CVP) could allow an authenticated, remote attacker to gain elevated privileges. The vulnerability is due to a lack of proper input validation. An attacker could exploit this vulnerability by authenticating to the OAMP and sending a crafted HTTP request. A successful exploit could allow the attacker to gain administrator privileges. The attacker must successfully authenticate to the system to exploit this vulnerability. This vulnerability affects Cisco Unified Customer Voice Portal (CVP) running software release 10.5, 11.0, or 11.5. Cisco Bug IDs: CSCve92752.

    Published: 21 Sept 2017
    7.1
    High

    CVE-2017-12215

    Last Modified: 20 Apr 2025

    A vulnerability in the email message filtering feature of Cisco AsyncOS Software for the Cisco Email Security Appliance could allow an unauthenticated, remote attacker to cause an affected device to run out of memory and stop scanning and forwarding email messages. When system memory is depleted, it can cause the filtering process to crash, resulting in a denial of service (DoS) condition on the device. This vulnerability affects software version 9.0 through the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to apply a message filter or content filter to incoming email attachments. The vulnerability is not limited to any specific rules or actions for a message filter or content filter. Cisco Bug IDs: CSCvd29354.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-12253

    Last Modified: 31 Jul 2025

    A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCve76872.

    Published: 21 Sept 2017
    6.1
    Medium

    CVE-2017-12248

    Last Modified: 31 Jul 2025

    A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by persuading a user to click a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76835.

    Published: 21 Sept 2017
    7.8
    High

    CVE-2017-12252

    Last Modified: 20 Apr 2025

    A vulnerability in the Cisco FindIT Network Discovery Utility could allow an authenticated, local attacker to perform a DLL preloading attack, potentially causing a partial impact to device availability, confidentiality, and integrity. The vulnerability is due to the application loading a malicious copy of a specific, nondefined DLL file instead of the DLL file it was expecting. An attacker could exploit this vulnerability by placing an affected DLL within the search path of the host system. An exploit could allow the attacker to load a malicious DLL file into the system, thus partially compromising confidentiality, integrity, and availability on the device. Cisco Bug IDs: CSCve89785.

    Published: 21 Sept 2017
    7.5
    High

    CVE-2017-12219

    Last Modified: 20 Apr 2025

    A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to the inability to handle many large IP fragments for reassembly in a short duration. An attacker could exploit this vulnerability by sending a crafted stream of IP fragments to the targeted device. An exploit could allow the attacker to cause a DoS condition when the device unexpectedly reloads. Cisco Bug IDs: CSCve82586.

    Published: 21 Sept 2017
    5.3
    Medium

    CVE-2017-12250

    Last Modified: 20 Apr 2025

    A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an HTTP Application Optimization (AO) related process to restart, causing a partial denial of service (DoS) condition. The vulnerability is due to lack of input validation of user-supplied input parameters within an HTTP request. An attacker could exploit this vulnerability by sending a crafted HTTP request through the targeted device. An exploit could allow the attacker to cause a DoS condition due to a process unexpectedly restarting. The WAAS could drop traffic during the brief time the process is restarting. Cisco Bug IDs: CSCvc63048.

    Published: 21 Sept 2017
    6.1
    Medium

    CVE-2017-12254

    Last Modified: 31 Jul 2025

    A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76848, CSCve76856.

    Published: 21 Sept 2017
    6.7
    Medium

    CVE-2017-12255

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI of Cisco UCS Central Software could allow an authenticated, local attacker to gain shell access. The vulnerability is due to insufficient input validation of commands entered in the CLI, aka a Restricted Shell Break Vulnerability. An attacker could exploit this vulnerability by entering a specific command with crafted arguments. An exploit could allow the attacker to gain shell access to the underlying system. Cisco Bug IDs: CSCve70762.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-6720

    Last Modified: 20 Apr 2025

    A vulnerability in the Secure Shell (SSH) subsystem of Cisco Small Business Managed Switches software could allow an authenticated, remote attacker to cause a reload of the affected switch, resulting in a denial of service (DoS) condition. The vulnerability is due to improper processing of SSH connections. An attacker could exploit this vulnerability by logging in to an affected switch via SSH and sending a malicious SSH message. This vulnerability affects the following Cisco products when SSH is enabled: Small Business 300 Series Managed Switches, Small Business 500 Series Stackable Managed Switches, 350 Series Managed Switches, 350X Series Stackable Managed Switches, 550X Series Stackable Managed Switches, ESW2 Series Advanced Switches. Cisco Bug IDs: CSCvb48377.

    Published: 21 Sept 2017
    8.1
    High

    CVE-2017-12617

    Last Modified: 25 Aug 2026

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    Published: 21 Sept 2017
    5.9
    Medium

    CVE-2017-14970

    Last Modified: 20 Apr 2025

    In lib/ofp-util.c in Open vSwitch (OvS) before 2.8.1, there are multiple memory leaks while parsing malformed OpenFlow group mod messages. NOTE: the vendor disputes the relevance of this report, stating "it can only be triggered by an OpenFlow controller, but OpenFlow controllers have much more direct and powerful ways to force Open vSwitch to allocate memory, such as by inserting flows into the flow table."

    Published: 21 Sept 2017