CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-13050

    Last Modified: 4 Dec 2025

    The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13052

    Last Modified: 20 Apr 2025

    The CFM parser in tcpdump before 4.9.2 has a buffer over-read in print-cfm.c:cfm_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13054

    Last Modified: 4 Dec 2025

    The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13725

    Last Modified: 20 Apr 2025

    The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

    Published: 13 Sept 2017
    9.1
    Critical

    CVE-2017-14608

    Last Modified: 20 Apr 2025

    In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to disclose potentially sensitive memory or cause an application crash.

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-2299

    Last Modified: 20 Apr 2025

    Versions of the puppetlabs-apache module prior to 1.11.1 and 2.1.0 make it very easy to accidentally misconfigure TLS trust. If you specify the `ssl_ca` parameter but do not specify the `ssl_certs_dir` parameter, a default will be provided for the `ssl_certs_dir` that will trust certificates from any of the system-trusted certificate authorities. This did not affect FreeBSD.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13020

    Last Modified: 4 Dec 2025

    The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12985

    Last Modified: 4 Dec 2025

    The IPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-ip6.c:ip6_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12990

    Last Modified: 4 Dec 2025

    The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12997

    Last Modified: 4 Dec 2025

    The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().

    Published: 13 Sept 2017
    7.5
    High

    CVE-2017-12989

    Last Modified: 20 Apr 2025

    The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13003

    Last Modified: 20 Apr 2025

    The LMP parser in tcpdump before 4.9.2 has a buffer over-read in print-lmp.c:lmp_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-14632

    Last Modified: 20 Apr 2025

    Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 550184.

    Published: 13 Sept 2017
    6.5
    Medium

    CVE-2017-18229

    Last Modified: 21 Nov 2024

    An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12902

    Last Modified: 4 Dec 2025

    The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12893

    Last Modified: 4 Dec 2025

    The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12895

    Last Modified: 4 Dec 2025

    The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12896

    Last Modified: 4 Dec 2025

    The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12897

    Last Modified: 4 Dec 2025

    The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12898

    Last Modified: 4 Dec 2025

    The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:interp_reply().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12899

    Last Modified: 4 Dec 2025

    The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12992

    Last Modified: 4 Dec 2025

    The RIPng parser in tcpdump before 4.9.2 has a buffer over-read in print-ripng.c:ripng_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12994

    Last Modified: 4 Dec 2025

    The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12995

    Last Modified: 4 Dec 2025

    The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-12996

    Last Modified: 4 Dec 2025

    The PIMv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c:pimv2_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13001

    Last Modified: 4 Dec 2025

    The NFS parser in tcpdump before 4.9.2 has a buffer over-read in print-nfs.c:nfs_printfh().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13002

    Last Modified: 4 Dec 2025

    The AODV parser in tcpdump before 4.9.2 has a buffer over-read in print-aodv.c:aodv_extension().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13006

    Last Modified: 4 Dec 2025

    The L2TP parser in tcpdump before 4.9.2 has a buffer over-read in print-l2tp.c, several functions.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13010

    Last Modified: 4 Dec 2025

    The BEEP parser in tcpdump before 4.9.2 has a buffer over-read in print-beep.c:l_strnstart().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13013

    Last Modified: 4 Dec 2025

    The ARP parser in tcpdump before 4.9.2 has a buffer over-read in print-arp.c, several functions.

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13015

    Last Modified: 4 Dec 2025

    The EAP parser in tcpdump before 4.9.2 has a buffer over-read in print-eap.c:eap_print().

    Published: 13 Sept 2017
    9.8
    Critical

    CVE-2017-13017

    Last Modified: 4 Dec 2025

    The DHCPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-dhcp6.c:dhcp6opt_print().

    Published: 13 Sept 2017
    4.8
    Medium

    CVE-2015-9230

    Last Modified: 20 Apr 2025

    In the admin/db-backup-security/db-backup-security.php page in the BulletProof Security plugin before .52.5 for WordPress, XSS is possible for remote authenticated administrators via the DBTablePrefix parameter.

    Published: 12 Sept 2017
    4.8
    Medium

    CVE-2015-9229

    Last Modified: 20 Apr 2025

    In the nggallery-manage-gallery page in the Photocrati NextGEN Gallery plugin 2.1.15 for WordPress, XSS is possible for remote authenticated administrators via the images[1][alttext] parameter.

    Published: 12 Sept 2017
    7.5
    High

    CVE-2017-1162

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957.

    Published: 12 Sept 2017
    4.7
    Medium

    CVE-2017-1434

    Last Modified: 20 Apr 2025

    IBM DB2 for Linux, UNIX and Windows 11.1 (includes DB2 Connect Server) under unusual circumstances, could expose highly sensitive information in the error log to a local user.

    Published: 12 Sept 2017
    3.7
    Low

    CVE-2017-1520

    Last Modified: 20 Apr 2025

    IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.

    Published: 12 Sept 2017
    5.5
    Medium

    CVE-2017-1352

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.

    Published: 12 Sept 2017
    6.7
    Medium

    CVE-2017-1438

    Last Modified: 20 Apr 2025

    IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128057.

    Published: 12 Sept 2017
    6.7
    Medium

    CVE-2017-1439

    Last Modified: 20 Apr 2025

    IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128058.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-14397

    Last Modified: 20 Apr 2025

    AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.

    Published: 12 Sept 2017
    8.8
    High

    CVE-2017-14399

    Last Modified: 20 Apr 2025

    In BlackCat CMS 1.2.2, unrestricted file upload is possible in backend\media\ajax_rename.php via the extension parameter, as demonstrated by changing the extension from .jpg to .php.

    Published: 12 Sept 2017
    5.9
    Medium

    CVE-2017-1519

    Last Modified: 20 Apr 2025

    IBM DB2 10.5 and 11.1 contains a denial of service vulnerability. A remote user can cause disruption of service for DB2 Connect Server setup with a particular configuration. IBM X-Force ID: 129829.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-14396

    Last Modified: 20 Apr 2025

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

    Published: 12 Sept 2017
    7.8
    High

    CVE-2017-1451

    Last Modified: 20 Apr 2025

    IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user with DB2 instance owner privileges to obtain root access. IBM X-Force ID: 128178.

    Published: 12 Sept 2017
    7.8
    High

    CVE-2017-1452

    Last Modified: 20 Apr 2025

    IBM DB2 for Linux, UNIX and Windows 9.7, 10,1, 10.5, and 11.1 (includes DB2 Connect Server) could allow a local user to obtain elevated privilege and overwrite DB2 files. IBM X-Force ID: 128180.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-8015

    Last Modified: 20 Apr 2025

    EMC AppSync (all versions prior to 3.5) contains a SQL injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 12 Sept 2017
    6.1
    Medium

    CVE-2017-14347

    Last Modified: 20 Apr 2025

    NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.

    Published: 12 Sept 2017
    8.8
    High

    CVE-2017-14348

    Last Modified: 20 Apr 2025

    LibRaw before 0.18.4 has a heap-based Buffer Overflow in the processCanonCameraInfo function via a crafted file.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-14345

    Last Modified: 20 Apr 2025

    SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.

    Published: 12 Sept 2017