CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-4180

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2009-4050.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2015-4181

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

    Published: 25 Aug 2017
    6.1
    Medium

    CVE-2017-13697

    Last Modified: 20 Apr 2025

    controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2016-5816

    Last Modified: 20 Apr 2025

    A Use of Hard-Coded Cryptographic Key issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded private cryptographic keys that may allow an attacker to decrypt traffic from any other source.

    Published: 25 Aug 2017
    8.8
    High

    CVE-2017-12703

    Last Modified: 20 Apr 2025

    A Cross-Site Request Forgery (CSRF) issue was discovered in Westermo MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The application does not verify whether a request was intentionally provided by the user, making it possible for an attacker to trick a user into making a malicious request to the server.

    Published: 25 Aug 2017
    5.3
    Medium

    CVE-2017-12709

    Last Modified: 20 Apr 2025

    A Use of Hard-Coded Credentials issue was discovered in MRD-305-DIN versions older than 1.7.5.0, and MRD-315, MRD-355, MRD-455 versions older than 1.7.5.0. The device utilizes hard-coded credentials, which could allow for unauthorized local low-privileged access to the device.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13748

    Last Modified: 20 Apr 2025

    There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13750

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    5.5
    Medium

    CVE-2017-13716

    Last Modified: 20 Apr 2025

    The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13749

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13751

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13746

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13747

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13752

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.

    Published: 25 Aug 2017
    7.5
    High

    CVE-2017-13745

    Last Modified: 20 Apr 2025

    There is a reachable assertion abort in the function jpc_dec_process_sot() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpc_ppmstabtostreams return value, a different vulnerability than CVE-2018-9154.

    Published: 25 Aug 2017
    6.5
    Medium

    CVE-2017-7562

    Last Modified: 21 Nov 2024

    An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote attacker able to communicate with the KDC could potentially use this flaw to impersonate arbitrary principals under rare and erroneous circumstances.

    Published: 25 Aug 2017
    9.8
    Critical

    CVE-2015-8352

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.

    Published: 24 Aug 2017
    8.8
    High

    CVE-2015-8355

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in the orion.extfeedbackform module before 2.1.3 for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) order or (2) "by" parameter to admin/orion.extfeedbackform_efbf_forms.php.

    Published: 24 Aug 2017
    6.1
    Medium

    CVE-2015-4699

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Splash Portal in Cloud4Wi before 5.9.7 allows remote attackers to inject arbitrary web script or HTML via the recoveryMessage parameter to the default URI.

    Published: 24 Aug 2017
    6.5
    Medium

    CVE-2015-7896

    Last Modified: 20 Apr 2025

    LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2015-7257

    Last Modified: 20 Apr 2025

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrator users to change the admin password by intercepting an outgoing password change request, and changing the username parameter from "support" to "admin".

    Published: 24 Aug 2017
    7.8
    High

    CVE-2015-8308

    Last Modified: 20 Apr 2025

    LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2015-1800

    Last Modified: 20 Apr 2025

    The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive information.

    Published: 24 Aug 2017
    9.8
    Critical

    CVE-2015-1801

    Last Modified: 20 Apr 2025

    The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges.

    Published: 24 Aug 2017
    8.8
    High

    CVE-2015-7258

    Last Modified: 20 Apr 2025

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain user passwords by displaying user information in a Telnet connection.

    Published: 24 Aug 2017
    8.8
    High

    CVE-2015-7259

    Last Modified: 20 Apr 2025

    ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid username and password pairs, which allows remote authenticated users to login to a target account via any of its username and password pairs.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2015-7516

    Last Modified: 20 Apr 2025

    ONOS before 1.5.0 when using the ifwd app allows remote attackers to cause a denial of service (NULL pointer dereference and switch disconnect) by sending two Ethernet frames with ether_type Jumbo Frame (0x8870).

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-12879

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS-STORED) vulnerability in the DEVICES OR SENSORS functionality in Paessler PRTG Network Monitor before 17.3.33.2654 allows authenticated remote attackers to inject arbitrary web script or HTML.

    Published: 24 Aug 2017
    6.1
    Medium

    CVE-2017-13671

    Last Modified: 20 Apr 2025

    app/View/Helper/CommandHelper.php in MISP before 2.4.79 has persistent XSS via comments. It only impacts the users of the same instance because the comment field is not part of the MISP synchronisation.

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-9555

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.0-3414 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2017-9511

    Last Modified: 20 Apr 2025

    The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.

    Published: 24 Aug 2017
    6.5
    Medium

    CVE-2017-12074

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.

    Published: 24 Aug 2017
    9.8
    Critical

    CVE-2017-13669

    Last Modified: 20 Apr 2025

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the setanswered parameter to staffbox.php.

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-9509

    Last Modified: 20 Apr 2025

    The review file upload resource in Atlassian Crucible before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the charset of a previously uploaded file.

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-9510

    Last Modified: 20 Apr 2025

    The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.

    Published: 24 Aug 2017
    9.8
    Critical

    CVE-2017-12679

    Last Modified: 20 Apr 2025

    SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-9507

    Last Modified: 20 Apr 2025

    The review dashboard resource in Atlassian Crucible from version 4.1.0 before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the review filter title parameter.

    Published: 24 Aug 2017
    5.4
    Medium

    CVE-2017-9508

    Last Modified: 20 Apr 2025

    Various resources in Atlassian Fisheye and Crucible before version 4.4.1 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the name of a repository or review file.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2017-9512

    Last Modified: 20 Apr 2025

    The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.

    Published: 24 Aug 2017
    5.5
    Medium

    CVE-2017-13666

    Last Modified: 20 Apr 2025

    An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x265 through 2.5, as used in libbpg and other products. A small height value can cause an integer underflow, which leads to a crash. This is a different vulnerability than CVE-2017-8906.

    Published: 24 Aug 2017
    7.8
    High

    CVE-2017-0805

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.

    Published: 24 Aug 2017
    6.5
    Medium

    CVE-2017-13673

    Last Modified: 20 Apr 2025

    The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot_get_dirty function.

    Published: 24 Aug 2017
    8.1
    High

    CVE-2017-14623

    Last Modified: 20 Apr 2025

    In the ldap.v2 (aka go-ldap) package through 2.5.0 for Go, an attacker may be able to login with an empty password. This issue affects an application using this package if these conditions are met: (1) it relies only on the return error of the Bind function call to determine whether a user is authorized (i.e., a nil return value is interpreted as successful authorization) and (2) it is used with an LDAP server allowing unauthenticated bind.

    Published: 24 Aug 2017
    7.5
    High

    CVE-2017-13692

    Last Modified: 20 Apr 2025

    In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an invalid ISALNUM argument.

    Published: 24 Aug 2017
    7
    High

    CVE-2017-17053

    Last Modified: 20 Apr 2025

    The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctly handle errors from LDT table allocation when forking a new process, allowing a local attacker to achieve a use-after-free or possibly have unspecified other impact by running a specially crafted program. This vulnerability only affected kernels built with CONFIG_MODIFY_LDT_SYSCALL=y.

    Published: 24 Aug 2017
    5.5
    Medium

    CVE-2017-18186

    Last Modified: 21 Nov 2024

    An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

    Published: 24 Aug 2017
    5.5
    Medium

    CVE-2017-13672

    Last Modified: 20 Apr 2025

    QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

    Published: 24 Aug 2017
    5.5
    Medium

    CVE-2017-13649

    Last Modified: 20 Apr 2025

    UnrealIRCd 4.0.13 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command. NOTE: the vendor indicates that there is no common or recommended scenario in which a root script would execute this kill command.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13648

    Last Modified: 20 Apr 2025

    In GraphicsMagick 1.3.26, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c.

    Published: 23 Aug 2017
    6.1
    Medium

    CVE-2017-9506

    Last Modified: 20 Apr 2025

    The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

    Published: 23 Aug 2017