CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-14160

    Last Modified: 20 Apr 2025

    The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14684

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-4 Q16, a memory leak vulnerability was found in the function ReadVIPSImage in coders/vips.c, which allows attackers to cause a denial of service (memory consumption in ResizeMagickMemory in MagickCore/memory.c) via a crafted file.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-14741

    Last Modified: 20 Apr 2025

    The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a crafted font file.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-14938

    Last Modified: 20 Apr 2025

    _bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-14939

    Last Modified: 20 Apr 2025

    decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-14974

    Last Modified: 20 Apr 2025

    The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.

    Published: 21 Sept 2017
    6.6
    Medium

    CVE-2017-16536

    Last Modified: 20 Apr 2025

    The cx231xx_usb_probe function in drivers/media/usb/cx231xx/cx231xx-cards.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 21 Sept 2017
    6.6
    Medium

    CVE-2017-16644

    Last Modified: 20 Apr 2025

    The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (improper error handling and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-5122

    Last Modified: 20 Apr 2025

    Inappropriate use of table size handling in V8 in Google Chrome prior to 61.0.3163.100 for Windows allowed a remote attacker to trigger out-of-bounds access via a crafted HTML page.

    Published: 21 Sept 2017
    6.5
    Medium

    CVE-2017-12190

    Last Modified: 20 Apr 2025

    The bio_map_user_iov and bio_unmap_user functions in block/bio.c in the Linux kernel before 4.13.8 do unbalanced refcounting when a SCSI I/O vector has small consecutive buffers belonging to the same page. The bio_add_pc_page function merges them into one, but the page reference is never dropped. This causes a memory leak and possible system lockup (exploitable against the host OS by a guest OS user, if a SCSI disk is passed through to a virtual machine) due to an out-of-memory condition.

    Published: 21 Sept 2017
    5.5
    Medium

    CVE-2017-14940

    Last Modified: 20 Apr 2025

    scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file.

    Published: 21 Sept 2017
    6.8
    Medium

    CVE-2017-16534

    Last Modified: 20 Apr 2025

    The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 21 Sept 2017
    8.8
    High

    CVE-2017-5121

    Last Modified: 20 Apr 2025

    Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to the escape analysis phase.

    Published: 21 Sept 2017
    5.4
    Medium

    CVE-2017-14621

    Last Modified: 20 Apr 2025

    Portus 2.2.0 has XSS via the Team field, related to typeahead.

    Published: 20 Sept 2017
    5.3
    Medium

    CVE-2015-9232

    Last Modified: 20 Apr 2025

    The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for its Authentication Delegation API intent. Also, the Good Dynamic application activation process does not attempt to detect malicious activation attempts involving modified names beginning with a com.good.gdgma substring. Consequently, an attacker could obtain access to intranet data. This issue is only relevant in cases where the user has already downloaded a malicious Android application.

    Published: 20 Sept 2017
    4.8
    Medium

    CVE-2017-14618

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2017-14619

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2015-9231

    Last Modified: 20 Apr 2025

    iTerm2 3.x before 3.1.1 allows remote attackers to discover passwords by reading DNS queries. A new (default) feature was added to iTerm2 version 3.0.0 (and unreleased 2.9.x versions such as 2.9.20150717) that resulted in a potential information disclosure. In an attempt to see whether the text under the cursor (or selected text) was a URL, the text would be sent as an unencrypted DNS query. This has the potential to result in passwords and other sensitive information being sent in cleartext without the user being aware.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2017-14615

    Last Modified: 20 Apr 2025

    An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged in user in the Web UI visiting "Traffic Monitor" sections "Events" and "All." As a side effect, no further events will be visible in the Traffic Monitor until the device is restarted.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2017-14616

    Last Modified: 20 Apr 2025

    An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management of the device becomes impossible.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2014-9758

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.

    Published: 20 Sept 2017
    5.3
    Medium

    CVE-2015-2826

    Last Modified: 20 Apr 2025

    WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.

    Published: 20 Sept 2017
    6.5
    Medium

    CVE-2015-2927

    Last Modified: 20 Apr 2025

    node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

    Published: 20 Sept 2017
    4.8
    Medium

    CVE-2015-7347

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.

    Published: 20 Sept 2017
    8.8
    High

    CVE-2015-5395

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SOGo before 3.1.0.

    Published: 20 Sept 2017
    7
    High

    CVE-2015-0162

    Last Modified: 20 Apr 2025

    IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2015-1866

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2015-3890

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in Open Litespeed before 1.3.10.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2015-4707

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.

    Published: 20 Sept 2017
    6.1
    Medium

    CVE-2015-5608

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in Joomla! CMS 3.0.0 through 3.4.1.

    Published: 20 Sept 2017
    9.8
    Critical

    CVE-2015-6673

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32.

    Published: 20 Sept 2017
    3.7
    Low

    CVE-2017-14595

    Last Modified: 20 Apr 2025

    In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

    Published: 20 Sept 2017
    9.8
    Critical

    CVE-2017-14596

    Last Modified: 20 Apr 2025

    In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

    Published: 20 Sept 2017
    7.8
    High

    CVE-2017-14609

    Last Modified: 20 Apr 2025

    The server daemons in Kannel 1.5.0 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by bearerbox.

    Published: 20 Sept 2017
    7.8
    High

    CVE-2017-14610

    Last Modified: 20 Apr 2025

    bareos-dir, bareos-fd, and bareos-sd in bareos-core in Bareos 16.2.6 and earlier create a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.

    Published: 20 Sept 2017
    9.8
    Critical

    CVE-2016-6795

    Last Modified: 20 Apr 2025

    In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for path traversal and execution of arbitrary code on server side.

    Published: 20 Sept 2017
    5.9
    Medium

    CVE-2016-8738

    Last Modified: 20 Apr 2025

    In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.

    Published: 20 Sept 2017
    7
    High

    CVE-2017-9607

    Last Modified: 5 Jun 2026

    The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2017-14339

    Last Modified: 20 Apr 2025

    The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.

    Published: 20 Sept 2017
    5
    Medium

    CVE-2017-9649

    Last Modified: 20 Apr 2025

    A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II, and MESH Repeater (Telemetry Enabled Devices). An unchangeable, factory-set key is included in the 900 MHz transmitter firmware.

    Published: 20 Sept 2017
    8.8
    High

    CVE-2015-1329

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.

    Published: 20 Sept 2017
    5.4
    Medium

    CVE-2015-4072

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.

    Published: 20 Sept 2017
    9.8
    Critical

    CVE-2015-4073

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2015-4074

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

    Published: 20 Sept 2017
    8.1
    High

    CVE-2015-4075

    Last Modified: 20 Apr 2025

    The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.

    Published: 20 Sept 2017
    8.8
    High

    CVE-2015-5607

    Last Modified: 20 Apr 2025

    Cross-site request forgery in the REST API in IPython 2 and 3.

    Published: 20 Sept 2017
    3.7
    Low

    CVE-2015-8224

    Last Modified: 20 Apr 2025

    Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remote attackers to obtain user equipment (aka UE) measurements of signal strengths.

    Published: 20 Sept 2017
    7.5
    High

    CVE-2017-7924

    Last Modified: 20 Apr 2025

    An Improper Input Validation issue was discovered in Rockwell Automation MicroLogix 1100 controllers 1763-L16BWA, 1763-L16AWA, 1763-L16BBB, and 1763-L16DWD. A remote, unauthenticated attacker could send a single, specially crafted Programmable Controller Communication Commands (PCCC) packet to the controller that could potentially cause the controller to enter a DoS condition.

    Published: 20 Sept 2017
    6.5
    Medium

    CVE-2017-9645

    Last Modified: 20 Apr 2025

    An Inadequate Encryption Strength issue was discovered in Mirion Technologies DMC 3000 Transmitter Module, iPam Transmitter f/DMC 2000, RDS-31 iTX and variants (including RSD31-AM Package), DRM-1/2 and variants (including Solar PWR Package), DRM and RDS Based Boundary Monitors, External Transmitters, Telepole II, and MESH Repeater (Telemetry Enabled Devices). Decryption of data is possible at the hardware level.

    Published: 20 Sept 2017
    9.8
    Critical

    CVE-2017-8771

    Last Modified: 20 Apr 2025

    On BE126 WIFI repeater 1.0 devices, an attacker can log into telnet (which is open by default) with default credentials as root (username:"root" password:"root"). The attacker can make a user that is connected to the repeater click on a malicious link that will log into the telnet and will infect the device with malicious code.

    Published: 20 Sept 2017