CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-14344

    Last Modified: 20 Apr 2025

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x95382673 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in a kernel pool overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-14346

    Last Modified: 20 Apr 2025

    upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.

    Published: 12 Sept 2017
    5.5
    Medium

    CVE-2017-8918

    Last Modified: 20 Apr 2025

    XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.

    Published: 12 Sept 2017
    8.1
    High

    CVE-2017-14337

    Last Modified: 20 Apr 2025

    When MISP before 2.4.80 is configured with X.509 certificate authentication (CertAuth) in conjunction with a non-MISP external user management ReST API, if an external user provides X.509 certificate authentication and this API returns an empty value, the unauthenticated user can be granted access as an arbitrary user.

    Published: 12 Sept 2017
    7.5
    High

    CVE-2017-14315

    Last Modified: 20 Apr 2025

    In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with attacker-controlled data. Since the audio commands sent via LEAP are not properly validated, an attacker can use this overflow to gain full control of the device through the relatively high privileges of the Bluetooth stack in iOS. The attack bypasses Bluetooth access control; however, the default "Bluetooth On" value must be present in Settings.

    Published: 12 Sept 2017
    7.5
    High

    CVE-2014-9624

    Last Modified: 20 Apr 2025

    CAPTCHA bypass vulnerability in MantisBT before 1.2.19.

    Published: 12 Sept 2017
    8.8
    High

    CVE-2015-9228

    Last Modified: 20 Apr 2025

    In post-new.php in the Photocrati NextGEN Gallery plugin 2.1.10 for WordPress, unrestricted file upload is available via the name parameter, if a file extension is changed from .jpg to .php.

    Published: 12 Sept 2017
    7.8
    High

    CVE-2017-14266

    Last Modified: 20 Apr 2025

    tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.

    Published: 12 Sept 2017
    7.5
    High

    CVE-2017-14335

    Last Modified: 20 Apr 2025

    On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

    Published: 12 Sept 2017
    6.1
    Medium

    CVE-2017-3133

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

    Published: 12 Sept 2017
    5.4
    Medium

    CVE-2017-3131

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

    Published: 12 Sept 2017
    6.1
    Medium

    CVE-2017-3132

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

    Published: 12 Sept 2017
    5.4
    Medium

    CVE-2017-7734

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.

    Published: 12 Sept 2017
    5.4
    Medium

    CVE-2017-7735

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups.

    Published: 12 Sept 2017
    9.1
    Critical

    CVE-2017-12883

    Last Modified: 20 Apr 2025

    Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.

    Published: 12 Sept 2017
    6.5
    Medium

    CVE-2017-1000250

    Last Modified: 20 Apr 2025

    All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

    Published: 12 Sept 2017
    6.6
    Medium

    CVE-2017-16528

    Last Modified: 20 Apr 2025

    sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-11281

    Last Modified: 20 Apr 2025

    Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

    Published: 12 Sept 2017
    7.1
    High

    CVE-2017-12154

    Last Modified: 20 Apr 2025

    The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel through 4.13.3 does not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allows KVM L2 guest OS users to obtain read and write access to the hardware CR8 register.

    Published: 12 Sept 2017
    5.6
    Medium

    CVE-2017-14317

    Last Modified: 20 Apr 2025

    A domain cleanup issue was discovered in the C xenstore daemon (aka cxenstored) in Xen through 4.9.x. When shutting down a VM with a stubdomain, a race in cxenstored may cause a double-free. The xenstored daemon may crash, resulting in a DoS of any parts of the system relying on it (including domain creation / destruction, ballooning, device changes, etc.).

    Published: 12 Sept 2017
    6.5
    Medium

    CVE-2017-14314

    Last Modified: 20 Apr 2025

    Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.

    Published: 12 Sept 2017
    9.8
    Critical

    CVE-2017-11282

    Last Modified: 20 Apr 2025

    Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

    Published: 12 Sept 2017
    6.1
    Medium

    CVE-2017-14313

    Last Modified: 20 Apr 2025

    The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of add_query_arg().

    Published: 12 Sept 2017
    6.5
    Medium

    CVE-2017-14318

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen 4.5.x through 4.9.x. The function `__gnttab_cache_flush` handles GNTTABOP_cache_flush grant table operations. It checks to see if the calling domain is the owner of the page that is to be operated on. If it is not, the owner's grant table is checked to see if a grant mapping to the calling domain exists for the page in question. However, the function does not check to see if the owning domain actually has a grant table or not. Some special domains, such as `DOMID_XEN`, `DOMID_IO` and `DOMID_COW` are created without grant tables. Hence, if __gnttab_cache_flush operates on a page owned by these special domains, it will attempt to dereference a NULL pointer in the domain struct.

    Published: 12 Sept 2017
    8.8
    High

    CVE-2017-14319

    Last Modified: 20 Apr 2025

    A grant unmapping issue was discovered in Xen through 4.9.x. When removing or replacing a grant mapping, the x86 PV specific path needs to make sure page table entries remain in sync with other accounting done. Although the identity of the page frame was validated correctly, neither the presence of the mapping nor page writability were taken into account.

    Published: 12 Sept 2017
    8
    High

    CVE-2017-1000251

    Last Modified: 20 Apr 2025

    The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

    Published: 12 Sept 2017
    7.5
    High

    CVE-2017-12837

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to cause a denial of service (out-of-bounds write) via a regular expression with a '\N{}' escape and the case-insensitive modifier.

    Published: 12 Sept 2017
    8.8
    High

    CVE-2017-14316

    Last Modified: 20 Apr 2025

    A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node that should be used for allocations through the `memflags` parameter; the node is extracted using the `MEMF_get_node` macro. While the function checks to see if the special constant `NUMA_NO_NODE` is specified, it otherwise does not handle the case where `node >= MAX_NUMNODES`. This allows an out-of-bounds access to an internal array.

    Published: 12 Sept 2017
    5.3
    Medium

    CVE-2015-4688

    Last Modified: 20 Apr 2025

    Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-5054

    Last Modified: 20 Apr 2025

    Open redirect vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.

    Published: 11 Sept 2017
    9
    Critical

    CVE-2015-8351

    Last Modified: 20 Apr 2025

    PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-8353

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers to inject arbitrary web script or HTML via the object_name parameter in a rs-object_role_edit page to wp-admin/admin.php.

    Published: 11 Sept 2017
    7.2
    High

    CVE-2015-9226

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_admin_download.php or remote authenticated users with a valid Paypal transaction token to execute arbitrary SQL commands via the ref parameter in the (3) orderUpdate function in upload/catalog/extension/payment/paypal.php.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2015-4689

    Last Modified: 20 Apr 2025

    Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-4687

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ellucian (formerly SunGard) Banner Student 8.5.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-8349

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-8350

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.php or (2) wp-cta-variation-id parameter to ab-testing-call-to-action-example/.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2015-8354

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ultimate Member WordPress plugin before 1.3.29 for WordPress allows remote attackers to inject arbitrary web script or HTML via the _refer parameter to wp-admin/users.php.

    Published: 11 Sept 2017
    7.2
    High

    CVE-2015-9227

    Last Modified: 20 Apr 2025

    PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14271

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlImpersonateSelfEx+0x000000000000024e."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14278

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005940."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14284

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlGetCurrentDirectory_U+0x000000000000016c."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14289

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllGetClassObject+0x000000000000303e."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14291

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x00000000000076d8."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14299

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x000000000000384b."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14307

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!TpAllocCleanupGroup+0x0000000000000402."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14270

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlFillMemoryUlong+0x0000000000000010."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14273

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x00000000000003b0."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14274

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at jbig2dec+0x0000000000008706."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14275

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 11 Sept 2017