CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-14260

    Last Modified: 20 Apr 2025

    In the SDK in Bento4 1.5.0-616, the AP4_StssAtom class in Ap4StssAtom.cpp contains a Write Memory Access Violation vulnerability. It is possible to exploit this vulnerability and possibly execute arbitrary code by opening a crafted .MP4 file.

    Published: 11 Sept 2017
    7.8
    High

    CVE-2017-14261

    Last Modified: 20 Apr 2025

    In the SDK in Bento4 1.5.0-616, the AP4_StszAtom class in Ap4StszAtom.cpp file contains a Read Memory Access Violation vulnerability. It is possible to exploit this vulnerability by opening a crafted .MP4 file.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2017-14268

    Last Modified: 20 Apr 2025

    EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices have XSS in the sms_content parameter in a getSMSlist request.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-14269

    Last Modified: 20 Apr 2025

    EE 4GEE WiFi MBB (before EE60_00_05.00_31) devices allow remote attackers to obtain sensitive information via a JSONP endpoint, as demonstrated by passwords and SMS content.

    Published: 11 Sept 2017
    8.1
    High

    CVE-2017-14263

    Last Modified: 20 Apr 2025

    Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

    Published: 11 Sept 2017
    6.1
    Medium

    CVE-2017-7554

    Last Modified: 20 Apr 2025

    It was found that the App Studio component of RHMAP 4.4 executes javascript provided by a user. An attacker could use this flaw to execute a stored XSS attack on an application administrator using App Studio.

    Published: 11 Sept 2017
    6.5
    Medium

    CVE-2017-14400

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause a denial of service (NULL pointer dereference in the function GetVirtualPixels in MagickCore/cache.c) via a crafted file.

    Published: 11 Sept 2017
    7.5
    High

    CVE-2017-14975

    Last Modified: 20 Apr 2025

    The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.

    Published: 11 Sept 2017
    6.3
    Medium

    CVE-2017-7553

    Last Modified: 20 Apr 2025

    The external_request api call in App Studio (millicore) allows server side request forgery (SSRF). An attacker could use this flaw to probe the network internal resources, and access restricted endpoints.

    Published: 11 Sept 2017
    9.8
    Critical

    CVE-2017-7552

    Last Modified: 20 Apr 2025

    A flaw was discovered in the file editor of millicore, affecting versions before 3.19.0 and 4.x before 4.5.0, which allows files to be executed as well as created. An attacker could use this flaw to compromise other users or teams projects stored in source control management of the RHMAP Core installation.

    Published: 11 Sept 2017
    5.3
    Medium

    CVE-2017-14231

    Last Modified: 20 Apr 2025

    GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php.

    Published: 10 Sept 2017
    8.1
    High

    CVE-2017-1000433

    Last Modified: 21 Nov 2024

    pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

    Published: 10 Sept 2017
    Unknown

    CVE-2017-14250

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 10 Sept 2017
    7.5
    High

    CVE-2017-14229

    Last Modified: 20 Apr 2025

    There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack.

    Published: 9 Sept 2017
    8.8
    High

    CVE-2017-14225

    Last Modified: 20 Apr 2025

    The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)

    Published: 9 Sept 2017
    7.1
    High

    CVE-2017-12699

    Last Modified: 20 Apr 2025

    An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to replace or modify original application files with malicious ones.

    Published: 9 Sept 2017
    6.5
    Medium

    CVE-2017-14222

    Last Modified: 20 Apr 2025

    In libavformat/mov.c in FFmpeg 3.3.3, a DoS in read_tfra() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MOV file, which claims a large "item_count" field in the header but does not contain sufficient backing data, is provided, the loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.

    Published: 9 Sept 2017
    6.5
    Medium

    CVE-2017-14223

    Last Modified: 20 Apr 2025

    In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain sufficient backing data, is provided, the for loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.

    Published: 9 Sept 2017
    5.3
    Medium

    CVE-2017-5147

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in AzeoTech DAQFactory versions prior to 17.1. An uncontrolled search path element vulnerability has been identified, which may execute malicious DLL files that have been placed within the search path.

    Published: 9 Sept 2017
    6.1
    Medium

    CVE-2017-8041

    Last Modified: 20 Apr 2025

    In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.

    Published: 9 Sept 2017
    9.8
    Critical

    CVE-2017-12731

    Last Modified: 20 Apr 2025

    A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via the input from the client.

    Published: 9 Sept 2017
    9.8
    Critical

    CVE-2017-12733

    Last Modified: 20 Apr 2025

    A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. An attacker may create an application user account to gain administrative privileges.

    Published: 9 Sept 2017
    6.5
    Medium

    CVE-2017-8040

    Last Modified: 20 Apr 2025

    In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed XML leading to exposure of data on the Single Sign-On service broker file system.

    Published: 9 Sept 2017
    7.8
    High

    CVE-2017-0753

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android libraries (libgdx). Product: Android. Versions: 7.1.1, 7.1.2, 8.0. Android ID: A-62218744.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0762

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62214264.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0770

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38234812.

    Published: 8 Sept 2017
    7.1
    High

    CVE-2017-0778

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0784

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0794

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Upstream kernel scsi driver. Product: Android. Versions: Android kernel. Android ID: A-35644812.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0752

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62196835.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0756

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0757

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36006815.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0759

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36715268.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0761

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0764

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0765

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872863.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0766

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libjhead). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37776688.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0767

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37536407.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0768

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62019992.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0769

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37662122.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0772

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38115076.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0773

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37615911.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0774

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62673844.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0775

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62673179.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0776

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0777

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0780

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android runtime (android messenger). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37742976.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0786

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37351060. References: B-V2017060101.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0787

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722970. References: B-V2017053104.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0790

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37357704. References: B-V2017053101.

    Published: 8 Sept 2017