CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-0791

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37306719. References: B-V2017052302.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-0792

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37305578. References: B-V2017052301.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0793

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the N/A memory subsystem. Product: Android. Versions: Android kernel. Android ID: A-35764946.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0795

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0796

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek auxadc driver. Product: Android. Versions: Android kernel. Android ID: A-62458865. References: M-ALPS03353884, M-ALPS03353886, M-ALPS03353887.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0799

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek lastbus. Product: Android. Versions: Android kernel. Android ID: A-36731602. References: M-ALPS03342072.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0800

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek teei. Product: Android. Versions: Android kernel. Android ID: A-37683975. References: M-ALPS03302988.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0801

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0802

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0803

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36136137. References: M-ALPS03361477.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0804

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek mmc driver. Product: Android. Versions: Android kernel. Android ID: A-36274676. References: M-ALPS03361487.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0755

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android libraries (libminikin). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-32178311.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0758

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0760

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0763

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62534693.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0771

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37624243.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-0779

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (audioflinger). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38340117.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0788

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37722328. References: B-V2017053103.

    Published: 8 Sept 2017
    8.8
    High

    CVE-2017-0789

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-37685267. References: B-V2017053102.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0797

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2017-0798

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36100671. References: M-ALPS03365532.

    Published: 8 Sept 2017
    7.8
    High

    CVE-2011-3177

    Last Modified: 20 Apr 2025

    The YaST2 network created files with world readable permissions which could have allowed local users to read sensitive material out of network configuration files, like passwords for wireless networks.

    Published: 8 Sept 2017
    7.5
    High

    CVE-2017-2550

    Last Modified: 20 Apr 2025

    Vulnerability in Easy Joomla Backup v3.2.4. The software creates a copy of the backup in the web root with an easily guessable filename.

    Published: 8 Sept 2017
    9.8
    Critical

    CVE-2017-11161

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-11162

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in synphotoio in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-12071

    Last Modified: 20 Apr 2025

    Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via the url parameter.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-9095

    Last Modified: 20 Apr 2025

    XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

    Published: 8 Sept 2017
    5.4
    Medium

    CVE-2017-11611

    Last Modified: 20 Apr 2025

    Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup" action, and the directory name in a "create-directory-popup" action, in the HTTP POST method to the "/plugin/file_manager/" script (aka an /admin/plugin/file_manager/browse// URI).

    Published: 8 Sept 2017
    7.5
    High

    CVE-2017-18214

    Last Modified: 21 Nov 2024

    The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-14926

    Last Modified: 20 Apr 2025

    In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-14324

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-14325

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadMPCImage in coders/mpc.c) via a crafted file.

    Published: 8 Sept 2017
    6.5
    Medium

    CVE-2017-14326

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-14928

    Last Modified: 20 Apr 2025

    In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

    Published: 8 Sept 2017
    7.5
    High

    CVE-2017-16113

    Last Modified: 21 Nov 2024

    The parsejson module is vulnerable to regular expression denial of service when untrusted user input is passed into it to be parsed.

    Published: 8 Sept 2017
    9.8
    Critical

    CVE-2017-14265

    Last Modified: 20 Apr 2025

    A Stack-based Buffer Overflow was discovered in xtrans_interpolate in internal/dcraw_common.cpp in LibRaw before 0.18.3. It could allow a remote denial of service or code execution attack.

    Published: 8 Sept 2017
    5.5
    Medium

    CVE-2017-14927

    Last Modified: 20 Apr 2025

    In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.

    Published: 8 Sept 2017
    6.1
    Medium

    CVE-2017-14219

    Last Modified: 20 Apr 2025

    XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e" command.

    Published: 7 Sept 2017
    4.4
    Medium

    CVE-2017-6795

    Last Modified: 20 Apr 2025

    A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite arbitrary files on the underlying operating system of an affected device. The vulnerability is due to improper input validation of the platform usb modem command in the CLI of the affected software. An attacker could exploit this vulnerability by modifying the platform usb modem command in the CLI of an affected device. A successful exploit could allow the attacker to overwrite arbitrary files on the underlying operating system of an affected device. Cisco Bug IDs: CSCvf10783.

    Published: 7 Sept 2017
    6.7
    Medium

    CVE-2017-6794

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root. Vulnerable Products: This vulnerability exists in Cisco Meeting Server software versions prior to and including 2.0, 2.1, and 2.2. Cisco Bug IDs: CSCvf53830.

    Published: 7 Sept 2017
    5.3
    Medium

    CVE-2017-12211

    Last Modified: 20 Apr 2025

    A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remote attacker to cause high CPU usage or a reload of the device. The vulnerability is due to IPv6 sub block corruption. An attacker could exploit this vulnerability by polling the affected device IPv6 information. An exploit could allow the attacker to trigger high CPU usage or a reload of the device. Known Affected Releases: Denali-16.3.1. Cisco Bug IDs: CSCvb14640.

    Published: 7 Sept 2017
    8.8
    High

    CVE-2017-12216

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file with malicious entries, which could allow the attacker to read and write files and execute remote code within the application. Cisco Bug IDs: CSCvf47946.

    Published: 7 Sept 2017
    6.5
    Medium

    CVE-2017-6792

    Last Modified: 20 Apr 2025

    A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in BatchFileName and Directory. An attacker could exploit this vulnerability by manipulating the parameters of the batch action file function. Cisco Bug IDs: CSCvd61766.

    Published: 7 Sept 2017
    4.3
    Medium

    CVE-2017-12213

    Last Modified: 20 Apr 2025

    A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. This could allow the attacker to pass traffic to the default VLAN of the affected port. The vulnerability is due to an uncaught error condition that may occur during the reassignment of the auth-default-ACL dynamic ACL to a switch port after 802.1x authentication fails. A successful exploit of this issue could allow a physically adjacent attacker to bypass 802.1x authentication and cause the affected port to fail open, allowing the attacker to pass traffic to the default VLAN of the affected switch port. Cisco Bug IDs: CSCvc72751.

    Published: 7 Sept 2017
    5.8
    Medium

    CVE-2017-12218

    Last Modified: 20 Apr 2025

    A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Appliances (ESAs) could allow an unauthenticated, remote attacker to cause an email attachment containing malware to be delivered to the end user. The vulnerability is due to the failure of AMP to scan certain EML attachments that could contain malware. An attacker could exploit this vulnerability by sending an email with a crafted EML attachment through the targeted device. A successful exploit could allow the attacker to bypass the configured ESA email message and content filtering and allow the malware to be delivered to the end user. Vulnerable Products: This vulnerability affects Cisco AsyncOS Software for Cisco ESA, both virtual and hardware appliances, that are configured with message or content filters to scan incoming email attachments on the ESA. Cisco Bug IDs: CSCuz81533.

    Published: 7 Sept 2017
    6.5
    Medium

    CVE-2017-12224

    Last Modified: 20 Apr 2025

    A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due to the incorrect implementation of the configuration setting Guest access via hyperlinks, which should allow the administrative user to prevent guest users from using hyperlinks to connect to meetings. An attacker could exploit this vulnerability by using a crafted hyperlink to connect to a meeting. An exploit could allow the attacker to connect directly to the meeting with a hyperlink, even though access should be denied. The attacker would still require a valid hyperlink and encoded secret identifier to be connected. Cisco Bug IDs: CSCve20873.

    Published: 7 Sept 2017
    6.5
    Medium

    CVE-2017-12225

    Last Modified: 20 Apr 2025

    A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow an authenticated, remote attacker to hijack another user's administrative session, aka a Session Fixation Vulnerability. The vulnerability is due to the reuse of a preauthentication session token as part of the postauthentication session. An attacker could exploit this vulnerability by obtaining the presession token ID. An exploit could allow an attacker to hijack an existing user's session. Known Affected Releases 4.2(5). Cisco Bug IDs: CSCvf58392.

    Published: 7 Sept 2017
    6.5
    Medium

    CVE-2017-6793

    Last Modified: 20 Apr 2025

    A vulnerability in the Inventory Management feature of Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to view sensitive information on the system. The vulnerability is due to insufficient protection of restricted information. An attacker could exploit this vulnerability by accessing unauthorized information via the user interface. Cisco Bug IDs: CSCvd61932.

    Published: 7 Sept 2017
    6.1
    Medium

    CVE-2017-6789

    Last Modified: 20 Apr 2025

    A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting (XSS) attack. The vulnerability occurs because user-supplied data in the DOM input is not validated. An attacker could exploit this vulnerability by sending crafted URLs that contain malicious DOM statements to the affected system. A successful exploit could allow the attacker to affect the integrity of the system by manipulating the database. Known Affected Releases 11.0(1)ES10. Cisco Bug IDs: CSCvf18325.

    Published: 7 Sept 2017
    7.5
    High

    CVE-2017-6791

    Last Modified: 20 Apr 2025

    A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of Transport Layer Security (TLS) traffic by the affected software. An attacker could exploit this vulnerability by generating incomplete traffic streams. A successful exploit could allow the attacker to deny access to the TVS for an affected device, resulting in a DoS condition, until an administrator restarts the service. Known Affected Releases 10.0(1.10000.24) 10.5(2.10000.5) 11.0(1.10000.10) 9.1(2.10000.28). Cisco Bug IDs: CSCux21905.

    Published: 7 Sept 2017