CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-10510

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php.

    Published: 31 Aug 2017
    7.5
    High

    CVE-2017-0901

    Last Modified: 20 Apr 2025

    RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2017-14076

    Last Modified: 20 Apr 2025

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2017-14069

    Last Modified: 20 Apr 2025

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the usernw array parameter to nowarn.php.

    Published: 31 Aug 2017
    6.1
    Medium

    CVE-2017-14070

    Last Modified: 20 Apr 2025

    Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14054

    Last Modified: 20 Apr 2025

    In libavformat/rmdec.c in FFmpeg 3.3.3, a DoS in ivr_read_header() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted IVR file, which claims a large "len" field in the header but does not contain sufficient backing data, is provided, the first type==4 loop would consume huge CPU resources, since there is no EOF check inside the loop.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14059

    Last Modified: 20 Apr 2025

    In FFmpeg 3.3.3, a DoS in cine_read_header() due to lack of an EOF check might cause huge CPU and memory consumption. When a crafted CINE file, which claims a large "duration" field in the header but does not contain sufficient backing data, is provided, the image-offset parsing loop would consume huge CPU and memory resources, since there is no EOF check inside the loop.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14055

    Last Modified: 20 Apr 2025

    In libavformat/mvdec.c in FFmpeg 3.3.3, a DoS in mv_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted MV file, which claims a large "nb_frames" field in the header but does not contain sufficient backing data, is provided, the loop over the frames would consume huge CPU and memory resources, since there is no EOF check inside the loop.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14056

    Last Modified: 20 Apr 2025

    In libavformat/rl2.c in FFmpeg 3.3.3, a DoS in rl2_read_header() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted RL2 file, which claims a large "frame_count" field in the header but does not contain sufficient backing data, is provided, the loops (for offset and size tables) would consume huge CPU and memory resources, since there is no EOF check inside these loops.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14057

    Last Modified: 20 Apr 2025

    In FFmpeg 3.3.3, a DoS in asf_read_marker() due to lack of an EOF (End of File) check might cause huge CPU and memory consumption. When a crafted ASF file, which claims a large "name_len" or "count" field in the header but does not contain sufficient backing data, is provided, the loops over the name and markers would consume huge CPU and memory resources, since there is no EOF check inside these loops.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14058

    Last Modified: 20 Apr 2025

    In FFmpeg 2.4 and 3.3.3, the read_data function in libavformat/hls.c does not restrict reload attempts for an insufficient list, which allows remote attackers to cause a denial of service (infinite loop).

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2017-13708

    Last Modified: 20 Apr 2025

    Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary code via a crafted GET request.

    Published: 31 Aug 2017
    5.4
    Medium

    CVE-2017-1449

    Last Modified: 20 Apr 2025

    IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128174.

    Published: 31 Aug 2017
    4.7
    Medium

    CVE-2016-0713

    Last Modified: 20 Apr 2025

    Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.

    Published: 31 Aug 2017
    5.4
    Medium

    CVE-2017-1444

    Last Modified: 20 Apr 2025

    IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128110.

    Published: 31 Aug 2017
    5.4
    Medium

    CVE-2017-1447

    Last Modified: 20 Apr 2025

    IBM Emptoris Sourcing 9.5 - 10.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128172.

    Published: 31 Aug 2017
    6.1
    Medium

    CVE-2017-1450

    Last Modified: 20 Apr 2025

    IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128177.

    Published: 31 Aug 2017
    7.8
    High

    CVE-2017-11158

    Last Modified: 20 Apr 2025

    Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Drive before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.

    Published: 31 Aug 2017
    5.4
    Medium

    CVE-2017-14049

    Last Modified: 20 Apr 2025

    In BlackCat CMS 1.2, backend/settings/ajax_save_settings.php allows remote authenticated users to conduct XSS attacks via the Website header or Website footer field.

    Published: 31 Aug 2017
    8.8
    High

    CVE-2017-14050

    Last Modified: 20 Apr 2025

    In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-13670

    Last Modified: 20 Apr 2025

    In BlackCat CMS 1.2, remote authenticated users can upload any file via the media upload function in backend/media/ajax_upload.php, as demonstrated by a ZIP archive that contains a .php file.

    Published: 31 Aug 2017
    8.8
    High

    CVE-2017-14048

    Last Modified: 20 Apr 2025

    BlackCat CMS 1.2 allows remote authenticated users to inject arbitrary PHP code into info.php via a crafted new_modulename parameter to backend/addons/ajax_create.php. NOTE: this can be exploited via CSRF.

    Published: 31 Aug 2017
    9.1
    Critical

    CVE-2017-14230

    Last Modified: 20 Apr 2025

    In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow remote attackers to obtain sensitive information or cause a denial of service (daemon crash) via a 'LIST "" "Other Users"' command.

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2015-7700

    Last Modified: 20 Apr 2025

    Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14249

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-8 Q16 mishandles EOF checks in ReadMPCImage in coders/mpc.c, leading to division by zero in GetPixelCacheTileSize in MagickCore/cache.c, allowing remote attackers to cause a denial of service via a crafted file.

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2017-0899

    Last Modified: 20 Apr 2025

    RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

    Published: 31 Aug 2017
    8.1
    High

    CVE-2017-0902

    Last Modified: 20 Apr 2025

    RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

    Published: 31 Aug 2017
    6.5
    Medium

    CVE-2017-14060

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixelCacheNexus function within the MagickCore/cache.c file) by submitting a malformed image file.

    Published: 31 Aug 2017
    9.8
    Critical

    CVE-2017-15047

    Last Modified: 20 Apr 2025

    The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application crash) or possibly have unspecified other impact by leveraging "limited access to the machine."

    Published: 31 Aug 2017
    8.8
    High

    CVE-2017-14041

    Last Modified: 20 Apr 2025

    A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

    Published: 30 Aug 2017
    6.5
    Medium

    CVE-2017-14042

    Last Modified: 20 Apr 2025

    A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.

    Published: 30 Aug 2017
    8.8
    High

    CVE-2017-14040

    Last Modified: 20 Apr 2025

    An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.

    Published: 30 Aug 2017
    5.5
    Medium

    CVE-2017-1441

    Last Modified: 20 Apr 2025

    IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106.

    Published: 30 Aug 2017
    6.1
    Medium

    CVE-2017-1443

    Last Modified: 20 Apr 2025

    IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128109.

    Published: 30 Aug 2017
    5.4
    Medium

    CVE-2017-1446

    Last Modified: 20 Apr 2025

    IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128171.

    Published: 30 Aug 2017
    6.1
    Medium

    CVE-2017-14038

    Last Modified: 20 Apr 2025

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has a redirect vulnerability.

    Published: 30 Aug 2017
    9.8
    Critical

    CVE-2017-14035

    Last Modified: 20 Apr 2025

    CrushFTP 8.x before 8.2.0 has a serialization vulnerability.

    Published: 30 Aug 2017
    6.1
    Medium

    CVE-2017-14036

    Last Modified: 20 Apr 2025

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.

    Published: 30 Aug 2017
    6.1
    Medium

    CVE-2017-14037

    Last Modified: 20 Apr 2025

    CrushFTP before 7.8.0 and 8.x before 8.2.0 has an HTTP header vulnerability.

    Published: 30 Aug 2017
    8.8
    High

    CVE-2017-1442

    Last Modified: 20 Apr 2025

    IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 128107.

    Published: 30 Aug 2017
    5.4
    Medium

    CVE-2017-1445

    Last Modified: 20 Apr 2025

    IBM Emptoris Spend Analysis 9.5.0.0 through 10.1.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128170.

    Published: 30 Aug 2017
    8.8
    High

    CVE-2017-1440

    Last Modified: 20 Apr 2025

    IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 128105.

    Published: 30 Aug 2017
    8.1
    High

    CVE-2017-14032

    Last Modified: 5 Jun 2026

    ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed TLS was formerly known as PolarSSL, the releases shipped with the PolarSSL name are not affected.

    Published: 30 Aug 2017
    7.8
    High

    CVE-2017-11157

    Last Modified: 20 Apr 2025

    Multiple untrusted search path vulnerabilities in the installer in Synology Cloud Station Backup before 4.2.5-4396 on Windows allow local attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.

    Published: 30 Aug 2017
    5.5
    Medium

    CVE-2016-5001

    Last Modified: 20 Apr 2025

    This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A local user on an HDFS DataNode may be able to craft a block token that grants unauthorized read access to random files by guessing certain fields in the token.

    Published: 30 Aug 2017
    7.4
    High

    CVE-2017-12735

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). An attacker who performs a Man-in-the-Middle attack between the LOGO! BM and other devices could potentially decrypt and modify network traffic.

    Published: 30 Aug 2017
    8.2
    High

    CVE-2017-12069

    Last Modified: 20 Apr 2025

    An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7 (All versions V8.1 and earlier), SIMATIC WinCC (All versions < V7.4 SP1), SIMATIC WinCC Runtime Professional (All versions < V14 SP1), SIMATIC NET PC Software, and SIMATIC IT Production Suite. By sending specially crafted packets to the OPC Discovery Server at port 4840/tcp, an attacker might cause the system to access various resources chosen by the attacker.

    Published: 30 Aug 2017
    7.5
    High

    CVE-2017-12734

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.

    Published: 30 Aug 2017
    6.5
    Medium

    CVE-2017-9945

    Last Modified: 20 Apr 2025

    In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requires a manual restart via the main device to recover.

    Published: 30 Aug 2017
    8.8
    High

    CVE-2017-12704

    Last Modified: 20 Apr 2025

    A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities where there is a lack of proper validation of the length of user-supplied data prior to copying it to the heap-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

    Published: 30 Aug 2017