CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2015-3654

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-4649.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2015-3655

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to hijack the authentication of administrators by leveraging improper enforcement of the anti-CSRF token.

    Published: 29 Aug 2017
    7.2
    High

    CVE-2015-3656

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain privileges by leveraging failure to properly enforce authorization checks.

    Published: 29 Aug 2017
    7.2
    High

    CVE-2015-3657

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.

    Published: 29 Aug 2017
    7.2
    High

    CVE-2015-4649

    Last Modified: 20 Apr 2025

    Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via unspecified vectors, a different vulnerability than CVE-2015-3654.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2015-6942

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.

    Published: 29 Aug 2017
    9.8
    Critical

    CVE-2015-7517

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2015-8334

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the Operation and Maintenance Unit (OMU) in Huawei VCN500 before V100R002C00SPC201 allows remote authenticated users to execute arbitrary SQL commands via a crafted HTTP request.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2017-11455

    Last Modified: 20 Apr 2025

    diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-12775

    Last Modified: 20 Apr 2025

    qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2017-12763

    Last Modified: 20 Apr 2025

    An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.

    Published: 29 Aug 2017
    5.5
    Medium

    CVE-2017-12797

    Last Modified: 20 Apr 2025

    Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause a denial of service via a crafted file, which triggers a heap-based buffer overflow.

    Published: 29 Aug 2017
    6.1
    Medium

    CVE-2017-12856

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2017-10952

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the saveAs JavaScript function. The issue results from the lack of proper validation of user-supplied data, which can lead to writing arbitrary files into attacker controlled locations. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4518.

    Published: 29 Aug 2017
    7
    High

    CVE-2017-10950

    Last Modified: 20 Apr 2025

    This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of the 0x8000E038 IOCTL in the bdfwfpf driver. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker could leverage this vulnerability to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4776.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2017-10951

    Last Modified: 20 Apr 2025

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within app.launchURL method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-4724.

    Published: 29 Aug 2017
    Unknown

    CVE-2017-13753

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9396. Reason: This candidate is a duplicate of CVE-2016-9396. Notes: All CVE users should reference CVE-2016-9396 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-13736

    Last Modified: 20 Apr 2025

    There are lots of memory leaks in the GMCommand function in magick/command.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-13737

    Last Modified: 20 Apr 2025

    There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.

    Published: 29 Aug 2017
    5.5
    Medium

    CVE-2017-13757

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to elf_i386_get_synthetic_symtab in elf32-i386.c and elf_x86_64_get_synthetic_symtab in elf64-x86-64.c.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-13765

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validation.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-13758

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the TracePoint() function in MagickCore/draw.c.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-13766

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-13764

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.

    Published: 29 Aug 2017
    7.5
    High

    CVE-2017-13767

    Last Modified: 20 Apr 2025

    In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.

    Published: 29 Aug 2017
    6.5
    Medium

    CVE-2017-14107

    Last Modified: 20 Apr 2025

    The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which allows remote attackers to cause a denial of service (memory allocation failure in _zip_cdir_grow in zip_dirent.c) via a crafted ZIP archive.

    Published: 29 Aug 2017
    7.8
    High

    CVE-2017-14333

    Last Modified: 20 Apr 2025

    The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have unspecified other impact via a crafted binary file with invalid values of ent.vn_next, during "readelf -a" execution.

    Published: 29 Aug 2017
    8.8
    High

    CVE-2015-8332

    Last Modified: 20 Apr 2025

    Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted message, aka "Horizontal Privilege Escalation Vulnerability."

    Published: 28 Aug 2017
    7.8
    High

    CVE-2015-8300

    Last Modified: 20 Apr 2025

    Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2014-8393

    Last Modified: 20 Apr 2025

    DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.

    Published: 28 Aug 2017
    5.4
    Medium

    CVE-2017-2255

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Space".

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10831

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    6.5
    Medium

    CVE-2017-10834

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-10840

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-1489

    Last Modified: 20 Apr 2025

    IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerability. ECSSO Master Authentication can redirect to a server not participating in an e-community domain. IBM X-Force ID: 128687.

    Published: 28 Aug 2017
    4.3
    Medium

    CVE-2016-2970

    Last Modified: 20 Apr 2025

    IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2014-8872

    Last Modified: 20 Apr 2025

    Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.

    Published: 28 Aug 2017
    4.9
    Medium

    CVE-2017-2254

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via specially crafted input

    Published: 28 Aug 2017
    5.4
    Medium

    CVE-2016-9732

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 6.0, 6.1, 6.2 and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119761.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10830

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Security Setup Tool all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10812

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Photo Collection PC Software Ver.4.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10826

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Security Kinou Mihariban v1.0.21 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10827

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Flets Azukeru for Windows Auto Backup Tool v1.0.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10828

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Flets Install Tool all versions distributed through the website till 2017 August 8 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    9.1
    Critical

    CVE-2017-10833

    Last Modified: 20 Apr 2025

    "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors.

    Published: 28 Aug 2017
    7.8
    High

    CVE-2017-10836

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Optimal Guard 1.1.21 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-10837

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Aug 2017
    6.1
    Medium

    CVE-2017-10838

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Aug 2017
    8.8
    High

    CVE-2017-10839

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Aug 2017
    9.8
    Critical

    CVE-2017-10842

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Aug 2017