CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-11357

    Last Modified: 22 Apr 2026

    Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

    Published: 23 Aug 2017
    9.8
    Critical

    CVE-2017-11317

    Last Modified: 21 Apr 2026

    Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-13147

    Last Modified: 20 Apr 2025

    In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-12970

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.

    Published: 23 Aug 2017
    9.8
    Critical

    CVE-2017-12965

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Published: 23 Aug 2017
    6.1
    Medium

    CVE-2017-12971

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.

    Published: 23 Aug 2017
    7.8
    High

    CVE-2017-11159

    Last Modified: 20 Apr 2025

    Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-12904

    Last Modified: 20 Apr 2025

    Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.

    Published: 23 Aug 2017
    9.8
    Critical

    CVE-2017-13137

    Last Modified: 20 Apr 2025

    The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.

    Published: 23 Aug 2017
    6.1
    Medium

    CVE-2017-13138

    Last Modified: 20 Apr 2025

    DOM based Cross-site scripting (XSS) vulnerability in the Bridge theme before 11.2 for WordPress allows remote attackers to inject arbitrary JavaScript.

    Published: 23 Aug 2017
    4.8
    Medium

    CVE-2017-12844

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.

    Published: 23 Aug 2017
    7.8
    High

    CVE-2017-13130

    Last Modified: 20 Apr 2025

    mcmnm in BMC Patrol allows local users to gain privileges via a crafted libmcmclnx.so file in the current working directory, because it is setuid root and the RPATH variable begins with the .: substring.

    Published: 23 Aug 2017
    9.8
    Critical

    CVE-2017-13139

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13144

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13131

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-8, a memory leak vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (memory consumption in NewLinkedList in MagickCore/linked-list.c) via a crafted file.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13140

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.9-1 and 7.x before 7.0.6-2, the ReadOnePNGImage function in coders/png.c allows remote attackers to cause a denial of service (application hang in LockSemaphoreInfo) via a PNG file with a width equal to MAGICK_WIDTH_LIMIT.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13142

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash because there was an insufficient check for short files.

    Published: 23 Aug 2017
    7.5
    High

    CVE-2017-13143

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13145

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13734

    Last Modified: 20 Apr 2025

    There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13741

    Last Modified: 20 Apr 2025

    There is a use-after-free in the function compileBrailleIndicator() in compileTranslationTable.c in Liblouis 3.2.0 that will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    9.8
    Critical

    CVE-2017-12858

    Last Modified: 20 Apr 2025

    Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13132

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-8, the WritePDFImage function in coders/pdf.c operates on an incorrect data structure in the "dump uncompressed PseudoColor packets" step, which allows attackers to cause a denial of service (assertion failure in WriteBlobStream in MagickCore/blob.c) via a crafted file.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13133

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-8, the load_level function in coders/xcf.c lacks offset validation, which allows attackers to cause a denial of service (load_tile memory exhaustion) via a crafted file.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13134

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13141

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.9-4 and 7.x before 7.0.6-4, a crafted file could trigger a memory leak in ReadOnePNGImage in coders/png.c.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-13146

    Last Modified: 20 Apr 2025

    In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13733

    Last Modified: 20 Apr 2025

    There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.

    Published: 23 Aug 2017
    7.5
    High

    CVE-2017-13728

    Last Modified: 20 Apr 2025

    There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13729

    Last Modified: 20 Apr 2025

    There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13730

    Last Modified: 20 Apr 2025

    There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13731

    Last Modified: 20 Apr 2025

    There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13732

    Last Modified: 20 Apr 2025

    There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-13738

    Last Modified: 20 Apr 2025

    There is an illegal address access in the _lou_getALine function in compileTranslationTable.c:346 in Liblouis 3.2.0.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-13740

    Last Modified: 20 Apr 2025

    There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function parseChars() in compileTranslationTable.c, that will lead to denial of service or possibly unspecified other impact.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13743

    Last Modified: 20 Apr 2025

    There is a buffer overflow in Liblouis 3.2.0, triggered in the function _lou_showString() in utils.c, that will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13744

    Last Modified: 20 Apr 2025

    There is an illegal address access in the function _lou_getALine() in compileTranslationTable.c:343 in Liblouis 3.2.0.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-14136

    Last Modified: 20 Apr 2025

    OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-12597.

    Published: 23 Aug 2017
    6
    Medium

    CVE-2017-15596

    Last Modified: 20 Apr 2025

    An issue was discovered in Xen 4.4.x through 4.9.x allowing ARM guest OS users to cause a denial of service (prevent physical CPU usage) because of lock mishandling upon detection of an add-to-physmap error.

    Published: 23 Aug 2017
    5.5
    Medium

    CVE-2017-18184

    Last Modified: 21 Nov 2024

    An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

    Published: 23 Aug 2017
    8.8
    High

    CVE-2017-13739

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow that causes a more than two thousand bytes out-of-bounds write in Liblouis 3.2.0, triggered in the function resolveSubtable() in compileTranslationTable.c. It will lead to denial of service or remote code execution.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-13742

    Last Modified: 20 Apr 2025

    There is a stack-based buffer overflow in Liblouis 3.2.0, triggered in the function includeFile() in compileTranslationTable.c, that will lead to a remote denial of service attack.

    Published: 23 Aug 2017
    6.5
    Medium

    CVE-2017-14528

    Last Modified: 20 Apr 2025

    The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.

    Published: 23 Aug 2017
    5.1
    Medium

    CVE-2017-7558

    Last Modified: 21 Nov 2024

    A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13. A data leak happens when these functions fill in sockaddr data structures used to export socket's diagnostic information. As a result, up to 100 bytes of the slab data could be leaked to a userspace.

    Published: 23 Aug 2017
    3.3
    Low

    CVE-2017-1422

    Last Modified: 20 Apr 2025

    IBM MaaS360 DTM all versions up to 3.81 does not perform proper verification for user rights of certain applications which could disclose sensitive information. IBM X-Force ID: 127412.

    Published: 22 Aug 2017
    8.8
    High

    CVE-2015-5258

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.

    Published: 22 Aug 2017
    9.8
    Critical

    CVE-2015-6472

    Last Modified: 20 Apr 2025

    WAGO IO 750-849 01.01.27 and 01.02.05, WAGO IO 750-881, and WAGO IO 758-870 have weak credential management.

    Published: 22 Aug 2017
    9.8
    Critical

    CVE-2015-6473

    Last Modified: 20 Apr 2025

    WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.

    Published: 22 Aug 2017
    9.8
    Critical

    CVE-2016-4460

    Last Modified: 20 Apr 2025

    Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.

    Published: 22 Aug 2017
    9.8
    Critical

    CVE-2017-12786

    Last Modified: 20 Apr 2025

    Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because there is a stack-based buffer overflow during unserialization of packet data.

    Published: 22 Aug 2017