CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2017-18043

    Last Modified: 21 Nov 2024

    Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).

    Published: 14 Sept 2017
    6.5
    Medium

    CVE-2017-14633

    Last Modified: 20 Apr 2025

    In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbis_analysis().

    Published: 14 Sept 2017
    9.1
    Critical

    CVE-2017-12249

    Last Modified: 20 Apr 2025

    A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information in an affected system. The vulnerability is due to an incorrect default configuration of the TURN server, which could expose internal interfaces and ports on the external interface of an affected system. An attacker could exploit this vulnerability by using a TURN server to perform an unauthorized connection to a Call Bridge, a Web Bridge, or a database cluster in an affected system, depending on the deployment model and CMS services in use. A successful exploit could allow the attacker to gain unauthenticated access to a Call Bridge or database cluster in an affected system or gain unauthorized access to sensitive meeting information in an affected system. To exploit this vulnerability, the attacker must have valid credentials for the TURN server of the affected system. This vulnerability affects Cisco Meeting Server (CMS) deployments that are running a CMS Software release prior to Release 2.0.16, 2.1.11, or 2.2.6. Cisco Bug IDs: CSCvf51127.

    Published: 13 Sept 2017
    6.7
    Medium

    CVE-2017-1508

    Last Modified: 20 Apr 2025

    IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.

    Published: 13 Sept 2017
    6.5
    Medium

    CVE-2017-1556

    Last Modified: 20 Apr 2025

    IBM API Connect 5.0.7.0 through 5.0.7.2 is vulnerable to a regular expression attack that could allow an authenticated attacker to use a regex and cause the system to slow or hang. IBM X-Force ID: 131546.

    Published: 13 Sept 2017
    8.8
    High

    CVE-2017-2816

    Last Modified: 20 Apr 2025

    An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14417

    Last Modified: 20 Apr 2025

    register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintended enrollment in mydlink Cloud Services.

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-14423

    Last Modified: 20 Apr 2025

    htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configuration via a series of requests.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14429

    Last Modified: 6 May 2025

    The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root because /etc/services/INET/inet_ipv4.php mishandles shell metacharacters, affecting generated files such as WAN-1-udhcpc.sh.

    Published: 13 Sept 2017
    8.1
    High

    CVE-2017-14418

    Last Modified: 20 Apr 2025

    The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices, sends the cleartext admin password over the Internet as part of interaction with mydlink Cloud Services.

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-14422

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14424

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/passwd permissions.

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-14430

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to cause a denial of service (daemon crash) via crafted LAN traffic.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2017-14413

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2017-14414

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2017-14415

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2017-14416

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wandetect.php.

    Published: 13 Sept 2017
    5.9
    Medium

    CVE-2017-14419

    Last Modified: 20 Apr 2025

    The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service for HTTPS is also established.

    Published: 13 Sept 2017
    5.9
    Medium

    CVE-2017-14420

    Last Modified: 20 Apr 2025

    The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14421

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14425

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapasswd permissions.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14426

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow (aka the /etc/shadow symlink target) permissions.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14427

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage_account_root permissions.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14428

    Last Modified: 20 Apr 2025

    D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/hostapd* permissions.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2015-2749

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.

    Published: 13 Sept 2017
    8.8
    High

    CVE-2016-8737

    Last Modified: 20 Apr 2025

    In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logged in to Brooklyn, would cause the server to execute the attacker's commands as the user. There is known to be a proof-of-concept exploit using this vulnerability.

    Published: 13 Sept 2017
    6.1
    Medium

    CVE-2015-2750

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in URL-related API functions in Drupal 6.x before 6.35 and 7.x before 7.35 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the "//" initial sequence.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2015-5168

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5206.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2015-5206

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in the HTTP/2 experimental feature in Apache Traffic Server before 5.3.x before 5.3.2 has unknown impact and attack vectors, a different vulnerability than CVE-2015-5168.

    Published: 13 Sept 2017
    4.3
    Medium

    CVE-2015-7880

    Last Modified: 20 Apr 2025

    The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.

    Published: 13 Sept 2017
    6.3
    Medium

    CVE-2017-14124

    Last Modified: 20 Apr 2025

    In eLux RP 5.x before 5.5.1000 LTSR and 5.6.x before 5.6.2 CR when classic desktop mode is used, it is possible to start applications other than defined, even if the user does not have permissions to change application definitions.

    Published: 13 Sept 2017
    5.4
    Medium

    CVE-2017-3165

    Last Modified: 20 Apr 2025

    In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to run in the browser of another user authorized to access the first user's resources. This is due to improper escaping of server-side content. There is known to be a proof-of-concept exploit using this vulnerability.

    Published: 13 Sept 2017
    8.8
    High

    CVE-2016-8744

    Last Modified: 20 Apr 2025

    Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML will allow unmarshalling to any Java type available on the classpath. This could provide an authenticated user with a means to cause the JVM running Brooklyn to load and run Java code without detection by Brooklyn. Such code would have the privileges of the Java process running Brooklyn, including the ability to open files and network connections, and execute system commands. There is known to be a proof-of-concept exploit using this vulnerability.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-12612

    Last Modified: 20 Apr 2025

    In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbitrary code execution by an attacker with access to any user account on the local machine. It does not affect apps run by spark-submit or spark-shell. The attacker would be able to execute code as the user that ran the Spark application. Users are encouraged to update to version 2.2.0 or later.

    Published: 13 Sept 2017
    6.5
    Medium

    CVE-2017-6330

    Last Modified: 20 Apr 2025

    Symantec Encryption Desktop before SED 10.4.1MP2 can allow remote attackers to cause a denial of service (resource consumption) via crafted web requests."

    Published: 13 Sept 2017
    5.5
    Medium

    CVE-2017-6007

    Last Modified: 20 Apr 2025

    A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to crash the OS via a malformed IOCTL call.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-11351

    Last Modified: 20 Apr 2025

    Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.

    Published: 13 Sept 2017
    8.8
    High

    CVE-2017-11350

    Last Modified: 20 Apr 2025

    Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices.

    Published: 13 Sept 2017
    5.4
    Medium

    CVE-2017-13724

    Last Modified: 20 Apr 2025

    On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the "Basic Settings" page.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-6008

    Last Modified: 20 Apr 2025

    A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-7441

    Last Modified: 20 Apr 2025

    In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a crafted IOCTL with code 0x22E1C0 might lead to kernel data leaks. Because the leak occurs at the driver level, an attacker can use this vulnerability to leak some critical information about the machine such as nt!ExpPoolQuotaCookie.

    Published: 13 Sept 2017
    7.8
    High

    CVE-2017-14398

    Last Modified: 20 Apr 2025

    rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and consequently gain privileges, via a methodology involving a handle to \Device\PhysicalMemory, IOCTL 0x22A064, and ZwMapViewOfSection.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14402

    Last Modified: 20 Apr 2025

    The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/add_modify_user.php in the "ACCOUNT CREATION" section, related to lack of input validation in include/function.php.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14403

    Last Modified: 20 Apr 2025

    The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search.php.

    Published: 13 Sept 2017
    5.5
    Medium

    CVE-2017-14410

    Last Modified: 20 Apr 2025

    A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-14404

    Last Modified: 20 Apr 2025

    The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_tool variable) to module/tool_all/select_tool.php, as demonstrated by a tool_list=php://filter/ substring.

    Published: 13 Sept 2017
    7.2
    High

    CVE-2017-14405

    Last Modified: 20 Apr 2025

    The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_cacti array parameter to module/admin_device/index.php.

    Published: 13 Sept 2017
    5.5
    Medium

    CVE-2017-14406

    Last Modified: 20 Apr 2025

    A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.

    Published: 13 Sept 2017
    5.5
    Medium

    CVE-2017-14407

    Last Modified: 20 Apr 2025

    A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.

    Published: 13 Sept 2017
    5.5
    Medium

    CVE-2017-14408

    Last Modified: 20 Apr 2025

    A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service.

    Published: 13 Sept 2017