CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-14276

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Possible Stack Corruption starting at jbig2dec+0x0000000000002fbe."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14277

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005956."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14280

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at jbig2dec+0x000000000000571d."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14281

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at jbig2dec+0x00000000000090f1."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14282

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005862."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14283

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000008fe4."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14286

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x000000000000cb8c."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14287

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "Read Access Violation on Control Flow starting at STDUJBIG2File+0x00000000000015eb."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14288

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllGetClassObject+0x0000000000002ff7."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14290

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Heap Corruption starting at wow64!Wow64NotifyDebugger+0x000000000000001d."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14293

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Heap Corruption starting at wow64!Wow64LdrpInitialize+0x00000000000008e1."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14294

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x000000000000566e."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14295

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls Code Flow starting at STDUJBIG2File+0x00000000000015e9."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14296

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x00000000000043e6."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14297

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls Code Flow starting at STDUJBIG2File!DllGetClassObject+0x0000000000002f35."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14298

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x00000000000038e8."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14300

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x0000000000004479."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14301

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllUnregisterServer+0x00000000000076d3."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14302

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at STDUJBIG2File!DllGetClassObject+0x00000000000064d7."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14303

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllGetClassObject+0x0000000000003047."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14304

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllGetClassObject+0x00000000000043e0."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14305

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at STDUJBIG2File!DllUnregisterServer+0x0000000000005578."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14306

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000006e10."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14309

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000006ec8."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14310

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000001869."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14272

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at jbig2dec+0x000000000000595d."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14279

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005643."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14285

    Last Modified: 20 Apr 2025

    XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlInterlockedPopEntrySList+0x000000000000039b."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14292

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x000000000000570e."

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14308

    Last Modified: 20 Apr 2025

    STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000006ddd."

    Published: 11 Sept 2017
    5.4
    Medium

    CVE-2015-7879

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Stickynote module 7.x before 7.x-1.3 for Drupal allows remote authenticated users with permission to create or edit a stickynote to inject arbitrary web script or HTML via note text on the admin listing page.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14075

    Last Modified: 20 Apr 2025

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824a7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in an out-of-bounds write condition. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Published: 11 Sept 2017
    9.3
    Critical

    CVE-2015-4523

    Last Modified: 20 Apr 2025

    Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2015-7877

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in the User Dashboard module 7.x before 7.x-1.4 for Drupal allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14153

    Last Modified: 20 Apr 2025

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824b7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in a kernel pool overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-7649

    Last Modified: 20 Apr 2025

    The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is left open, allowing to log into Kura without any user credentials over unencrypted telnet and executing commands using the Equinox "exec" command. As the process is running as "root" full control over the device can be acquired. IPv6 is also left in auto-configuration mode, accepting router advertisements automatically and assigns a MAC address based IPv6 address.

    Published: 11 Sept 2017
    6.5
    Medium

    CVE-2017-7650

    Last Modified: 20 Apr 2025

    In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party authentication/access control plugins for Mosquitto.

    Published: 11 Sept 2017
    5.4
    Medium

    CVE-2017-14239

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-14252

    Last Modified: 20 Apr 2025

    SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the group_id cookie to side.php.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14257

    Last Modified: 20 Apr 2025

    In the SDK in Bento4 1.5.0-616, AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14259

    Last Modified: 20 Apr 2025

    In the SDK in Bento4 1.5.0-616, the AP4_StscAtom class in Ap4StscAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

    Published: 11 Sept 2017
    8.1
    High

    CVE-2017-14262

    Last Modified: 20 Apr 2025

    On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.

    Published: 11 Sept 2017
    8.8
    High

    CVE-2017-14267

    Last Modified: 20 Apr 2025

    EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have CSRF, related to goform/AddNewProfile, goform/setWanDisconnect, goform/setSMSAutoRedirectSetting, goform/setReset, and goform/uploadBackupSettings.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14258

    Last Modified: 20 Apr 2025

    In the SDK in Bento4 1.5.0-616, SetItemCount in Core/Ap4StscAtom.h file contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-14238

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.

    Published: 11 Sept 2017
    7.5
    High

    CVE-2017-14240

    Last Modified: 20 Apr 2025

    There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.

    Published: 11 Sept 2017
    5.4
    Medium

    CVE-2017-14241

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-14242

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-14247

    Last Modified: 20 Apr 2025

    SQL Injection exists in the EyesOfNetwork web interface (aka eonweb) 5.1-0 via the user_id cookie to header.php, a related issue to CVE-2017-1000060.

    Published: 11 Sept 2017
    8.8
    High

    CVE-2017-14251

    Last Modified: 20 Apr 2025

    Unrestricted File Upload vulnerability in the fileDenyPattern in sysext/core/Classes/Core/SystemEnvironmentBuilder.php in TYPO3 7.6.0 to 7.6.21 and 8.0.0 to 8.7.4 allows remote authenticated users to upload files with a .pht extension and consequently execute arbitrary PHP code.

    Published: 11 Sept 2017