CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2015-9069

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrupted.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9070

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9071

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9072

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syscall.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-9073

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syscall.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10343

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, sSL handshake failure with ClientHello rejection results in memory leak.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10381

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send unprotected MeasurementReports revealing UE location.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10382

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.

    Published: 18 Aug 2017
    8.1
    High

    CVE-2016-10383

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, there is a TOCTOU race condition in Secure UI.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10386

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10387

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10388

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a configuration vulnerability exists when loading a 3rd-party QTEE application.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10390

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, when downloading a file, an excessive amount of memory may be consumed.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10391

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-10392

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2016-5872

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validated.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12881

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.

    Published: 18 Aug 2017
    5.4
    Medium

    CVE-2017-12882

    Last Modified: 20 Apr 2025

    Stored Cross-site scripting (XSS) vulnerability in Spring Batch Admin before 1.3.0 allows remote authenticated users to inject arbitrary JavaScript or HTML via the file upload functionality.

    Published: 18 Aug 2017
    7.2
    High

    CVE-2017-12946

    Last Modified: 20 Apr 2025

    classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in a delete action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12949

    Last Modified: 20 Apr 2025

    lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.

    Published: 18 Aug 2017
    7
    High

    CVE-2017-8267

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in an IOCTL handler potentially leading to an integer overflow and then an out-of-bounds write.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8253

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is sent from userspace.

    Published: 18 Aug 2017
    5.5
    Medium

    CVE-2017-8254

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an audio client pointer is dereferenced before being checked if it is valid.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8255

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in boot.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8256

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 multicast addresses.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8261

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in a camera driver ioctl, a kernel overwrite can potentially occur.

    Published: 18 Aug 2017
    7
    High

    CVE-2017-8262

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in some memory allocation and free functions, a race condition can potentially occur leading to a Use After Free condition.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8263

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a kernel fault can occur when doing certain operations on a read-only virtual address in userspace.

    Published: 18 Aug 2017
    7
    High

    CVE-2017-8265

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver which can lead to a double free.

    Published: 18 Aug 2017
    7
    High

    CVE-2017-8266

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to a use-after-free condition.

    Published: 18 Aug 2017
    7
    High

    CVE-2017-8270

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, a race condition exists in a driver potentially leading to a use-after-free condition.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8272

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, in a driver function, a value from userspace is not properly validated potentially leading to an out of bounds heap write.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8257

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, when accessing the sde_rotator debug interface for register reading with multiple processes, one process can free the debug buffer while another process still has the debug buffer in use.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-8260

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and cause an out of bounds write later.

    Published: 18 Aug 2017
    7.8
    High

    CVE-2017-11653

    Last Modified: 20 Apr 2025

    Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNativeLOC.dll file.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12592

    Last Modified: 20 Apr 2025

    ASUS DSL-N10S V2.1.16_APAC devices have a privilege escalation vulnerability. A normal user can escalate its privilege and perform administrative actions. There is no mapping of users with their privileges.

    Published: 18 Aug 2017
    7.5
    High

    CVE-2015-7945

    Last Modified: 20 Apr 2025

    The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2 allows remote attackers to obtain the DRBD secret via instance information job results.

    Published: 18 Aug 2017
    7.5
    High

    CVE-2015-7944

    Last Modified: 20 Apr 2025

    The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.13.x before 2.13.3, 2.14.x before 2.14.2, and 2.15.x before 2.15.2, when used in SSL mode, allows remote attackers to cause a denial of service (resource consumption) via SSL parameter renegotiation.

    Published: 18 Aug 2017
    5.5
    Medium

    CVE-2017-0687

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35583675.

    Published: 18 Aug 2017
    8.4
    High

    CVE-2017-11652

    Last Modified: 20 Apr 2025

    Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12420

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated users to cause a denial of service or execute arbitrary code.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12589

    Last Modified: 20 Apr 2025

    ToMAX R60G R60GV2-V2.0-v.2.6.3-170330 devices do not have any protection against a CSRF attack.

    Published: 18 Aug 2017
    5.4
    Medium

    CVE-2017-12591

    Last Modified: 20 Apr 2025

    ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2017-12776

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.

    Published: 18 Aug 2017
    8.8
    High

    CVE-2017-12593

    Last Modified: 20 Apr 2025

    ASUS DSL-N10S V2.1.16_APAC devices allow CSRF.

    Published: 18 Aug 2017
    9.8
    Critical

    CVE-2015-1817

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors.

    Published: 18 Aug 2017
    6.8
    Medium

    CVE-2015-1878

    Last Modified: 20 Apr 2025

    Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.

    Published: 18 Aug 2017
    6.5
    Medium

    CVE-2015-4082

    Last Modified: 20 Apr 2025

    attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".

    Published: 18 Aug 2017
    7.8
    High

    CVE-2015-3649

    Last Modified: 20 Apr 2025

    The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created.

    Published: 18 Aug 2017
    6.1
    Medium

    CVE-2017-12680

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in NexusPHP 1.5 via the type parameter to shoutbox.php.

    Published: 18 Aug 2017