CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-14626

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.

    Published: 3 Sept 2017
    8.8
    High

    CVE-2017-15017

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.

    Published: 3 Sept 2017
    8.8
    High

    CVE-2017-15016

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.

    Published: 3 Sept 2017
    7.5
    High

    CVE-2017-14099

    Last Modified: 20 Apr 2025

    In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized data disclosure (media takeover in the RTP stack) is possible with careful timing by an attacker. The "strictrtp" option in rtp.conf enables a feature of the RTP stack that learns the source address of media for a session and drops any packets that do not originate from the expected address. This option is enabled by default in Asterisk 11 and above. The "nat" and "rtp_symmetric" options (for chan_sip and chan_pjsip, respectively) enable symmetric RTP support in the RTP stack. This uses the source address of incoming media as the target address of any sent media. This option is not enabled by default, but is commonly enabled to handle devices behind NAT. A change was made to the strict RTP support in the RTP stack to better tolerate late media when a reinvite occurs. When combined with the symmetric RTP support, this introduced an avenue where media could be hijacked. Instead of only learning a new address when expected, the new code allowed a new source address to be learned at all times. If a flood of RTP traffic was received, the strict RTP support would allow the new address to provide media, and (with symmetric RTP enabled) outgoing traffic would be sent to this new address, allowing the media to be hijacked. Provided the attacker continued to send traffic, they would continue to receive traffic as well.

    Published: 2 Sept 2017
    6.5
    Medium

    CVE-2017-14114

    Last Modified: 20 Apr 2025

    RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recipient of RTP traffic, which allows remote attackers to obtain sensitive information or cause a denial of service (communication outage) via crafted RTP packets.

    Published: 2 Sept 2017
    9.8
    Critical

    CVE-2017-14100

    Last Modified: 20 Apr 2025

    In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan application. The application uses the caller-id name and number as part of a built string passed to the OS shell for interpretation and execution. Since the caller-id name and number can come from an untrusted source, a crafted caller-id name or number allows an arbitrary shell command injection.

    Published: 2 Sept 2017
    7.5
    High

    CVE-2017-14098

    Last Modified: 20 Apr 2025

    In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact header could cause Asterisk to crash.

    Published: 2 Sept 2017
    5.5
    Medium

    CVE-2017-14108

    Last Modified: 20 Apr 2025

    libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters.

    Published: 2 Sept 2017
    6.5
    Medium

    CVE-2017-14531

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.

    Published: 2 Sept 2017
    6.5
    Medium

    CVE-2016-1895

    Last Modified: 20 Apr 2025

    NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling.

    Published: 1 Sept 2017
    7.7
    High

    CVE-2017-12423

    Last Modified: 20 Apr 2025

    NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vectors.

    Published: 1 Sept 2017
    8.8
    High

    CVE-2017-12421

    Last Modified: 20 Apr 2025

    NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors.

    Published: 1 Sept 2017
    5.9
    Medium

    CVE-2017-12871

    Last Modified: 20 Apr 2025

    The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

    Published: 1 Sept 2017
    5.9
    Medium

    CVE-2017-12872

    Last Modified: 20 Apr 2025

    The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

    Published: 1 Sept 2017
    9.8
    Critical

    CVE-2017-12873

    Last Modified: 20 Apr 2025

    SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

    Published: 1 Sept 2017
    7.5
    High

    CVE-2017-12874

    Last Modified: 20 Apr 2025

    The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

    Published: 1 Sept 2017
    7.5
    High

    CVE-2017-14053

    Last Modified: 20 Apr 2025

    NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an HTTP session.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-14105

    Last Modified: 20 Apr 2025

    HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker - even restricted as a tenant - can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface).

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-10849

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Self-extracting document generated by DocuWorks 8.0.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-10850

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.), PostScript? Driver + Additional Feature Plug-in + PPD File for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:10 UTC.), XPS Print Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 3 Nov 2017 23:48 UTC.), ART EX Direct FAX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 26 May 2017 07:44 UTC.), Setting Restore Tool for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 25 Aug 2015 08:51 UTC.) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-10829

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Remote Support Tool (Enkaku Support Tool) All versions distributed through the website till 2017 August 10 allow an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-10848

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installers for DocuWorks 8.0.7 and earlier and DocuWorks Viewer Light published in Jul 2017 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-10851

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer for ContentsBridge Utility for Windows 7.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 1 Sept 2017
    7.5
    High

    CVE-2017-12869

    Last Modified: 20 Apr 2025

    The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

    Published: 1 Sept 2017
    8.8
    High

    CVE-2017-14103

    Last Modified: 20 Apr 2025

    The ReadJNGImage and ReadOneJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 do not properly manage image pointers after certain error conditions, which allows remote attackers to conduct use-after-free attacks via a crafted file, related to a ReadMNGImage out-of-order CloseBlob call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-11403.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-13674

    Last Modified: 20 Apr 2025

    Symantec ProxyClient 3.4 for Windows is susceptible to a privilege escalation vulnerability. A malicious local Windows user can, under certain circumstances, exploit this vulnerability to escalate their privileges on the system and execute arbitrary code with LocalSystem privileges.

    Published: 1 Sept 2017
    9.8
    Critical

    CVE-2017-3897

    Last Modified: 20 Apr 2025

    A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

    Published: 1 Sept 2017
    9.8
    Critical

    CVE-2015-7746

    Last Modified: 20 Apr 2025

    NetApp Data ONTAP before 8.2.4, when operating in 7-Mode, allows remote attackers to bypass authentication and (1) obtain sensitive information from or (2) modify volumes via vectors related to UTF-8 in the volume language.

    Published: 1 Sept 2017
    9.8
    Critical

    CVE-2017-12868

    Last Modified: 20 Apr 2025

    The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

    Published: 1 Sept 2017
    5.9
    Medium

    CVE-2017-12870

    Last Modified: 20 Apr 2025

    SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.

    Published: 1 Sept 2017
    5.9
    Medium

    CVE-2017-3898

    Last Modified: 20 Apr 2025

    A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.

    Published: 1 Sept 2017
    7.8
    High

    CVE-2017-14102

    Last Modified: 20 Apr 2025

    MIMEDefang 2.80 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command, as demonstrated by the init-script.in and mimedefang-init.in scripts.

    Published: 1 Sept 2017
    6.5
    Medium

    CVE-2017-12691

    Last Modified: 20 Apr 2025

    The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

    Published: 1 Sept 2017
    6.5
    Medium

    CVE-2017-12693

    Last Modified: 20 Apr 2025

    The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted BMP file.

    Published: 1 Sept 2017
    5.5
    Medium

    CVE-2017-14128

    Last Modified: 20 Apr 2025

    The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read_1_byte heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 1 Sept 2017
    6.5
    Medium

    CVE-2017-14132

    Last Modified: 20 Apr 2025

    JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.0.10, 2.0.11, 2.0.12, 2.0.13, 2.0.14, 2.0.15, 2.0.16 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jas_image_ishomosamp function in libjasper/base/jas_image.c.

    Published: 1 Sept 2017
    6.5
    Medium

    CVE-2017-12692

    Last Modified: 20 Apr 2025

    The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted VIFF file.

    Published: 1 Sept 2017
    5.5
    Medium

    CVE-2017-14106

    Last Modified: 20 Apr 2025

    The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel before 4.12 allows local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path.

    Published: 1 Sept 2017
    5.5
    Medium

    CVE-2017-14130

    Last Modified: 20 Apr 2025

    The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (_bfd_elf_attr_strdup heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 1 Sept 2017
    6.5
    Medium

    CVE-2017-14248

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file.

    Published: 1 Sept 2017
    7.5
    High

    CVE-2014-8675

    Last Modified: 20 Apr 2025

    Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash.

    Published: 31 Aug 2017
    5.3
    Medium

    CVE-2014-8676

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in a URL path parameter.

    Published: 31 Aug 2017
    5.3
    Medium

    CVE-2014-8677

    Last Modified: 20 Apr 2025

    The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.

    Published: 31 Aug 2017
    8.8
    High

    CVE-2015-5958

    Last Modified: 20 Apr 2025

    phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.

    Published: 31 Aug 2017
    6.1
    Medium

    CVE-2015-7711

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in popuphelp.php in ATutor 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the h parameter.

    Published: 31 Aug 2017
    7.3
    High

    CVE-2016-5795

    Last Modified: 20 Apr 2025

    An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and Carrier i-Vu Version 6.5 and prior. An attacker could enter malicious input to WebCTRL, i-Vu, or SiteScan Web through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

    Published: 31 Aug 2017
    6.1
    Medium

    CVE-2017-7855

    Last Modified: 20 Apr 2025

    In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.

    Published: 31 Aug 2017
    7.5
    High

    CVE-2017-0900

    Last Modified: 20 Apr 2025

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

    Published: 31 Aug 2017
    6.1
    Medium

    CVE-2016-10508

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpThumb() before 1.7.14 allow remote attackers to inject arbitrary web script or HTML via parameters in demo/phpThumb.demo.showpic.php.

    Published: 31 Aug 2017
    7.2
    High

    CVE-2016-10509

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 allows remote authenticated administrators to execute arbitrary SQL commands via a carrier (aka courier_id) parameter to openbay.php.

    Published: 31 Aug 2017