CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-6788

    Last Modified: 20 Apr 2025

    The WebLaunch functionality of Cisco AnyConnect Secure Mobility Client Software contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected software. The vulnerability is due to insufficient input validation of some parameters that are passed to the WebLaunch function of the affected software. An attacker could exploit this vulnerability by convincing a user to access a malicious link or by intercepting a user request and injecting malicious code into the request. Cisco Bug IDs: CSCvf12055. Known Affected Releases: 98.89(40).

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-11664

    Last Modified: 20 Apr 2025

    The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.

    Published: 17 Aug 2017
    9.8
    Critical

    CVE-2011-0469

    Last Modified: 20 Apr 2025

    Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.

    Published: 17 Aug 2017
    7.5
    High

    CVE-2017-11661

    Last Modified: 20 Apr 2025

    The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.

    Published: 17 Aug 2017
    7.5
    High

    CVE-2017-11662

    Last Modified: 20 Apr 2025

    The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-11663

    Last Modified: 20 Apr 2025

    The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12445

    Last Modified: 20 Apr 2025

    The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12442

    Last Modified: 20 Apr 2025

    The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12443

    Last Modified: 20 Apr 2025

    The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12444

    Last Modified: 20 Apr 2025

    The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12441

    Last Modified: 20 Apr 2025

    The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.

    Published: 17 Aug 2017
    4.7
    Medium

    CVE-2018-16888

    Last Modified: 21 Nov 2024

    It was discovered systemd does not correctly check the content of PIDFile files before using it to kill processes. When a service is run from an unprivileged user (e.g. User field set in the service file), a local attacker who is able to write to the PIDFile of the mentioned service may use this flaw to trick systemd into killing other services and/or privileged processes. Versions before v237 are vulnerable.

    Published: 17 Aug 2017
    8.8
    High

    CVE-2017-12955

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26. The vulnerability causes an out-of-bounds write in Exiv2::Image::printIFDStructure(), which may lead to remote denial of service or possibly unspecified other impact.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12956

    Last Modified: 20 Apr 2025

    There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.

    Published: 17 Aug 2017
    7.5
    High

    CVE-2017-12440

    Last Modified: 20 Apr 2025

    Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allows remote authenticated users with knowledge of trust IDs where Aodh is the trustee to obtain a Keystone token and perform unspecified authenticated actions by adding an alarm action with the scheme trust+http, and providing a trust id where Aodh is the trustee.

    Published: 17 Aug 2017
    6.5
    Medium

    CVE-2017-12957

    Last Modified: 20 Apr 2025

    There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to remote denial of service.

    Published: 17 Aug 2017
    9.8
    Critical

    CVE-2017-7555

    Last Modified: 20 Apr 2025

    Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the application using augeas to copy past the end of a buffer, leading to a crash or possible code execution.

    Published: 17 Aug 2017
    7.8
    High

    CVE-2017-12892

    Last Modified: 20 Apr 2025

    Foxit PDF Compressor installers from versions from 7.0.0.183 to 7.7.2.10 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.

    Published: 16 Aug 2017
    8.8
    High

    CVE-2016-5861

    Last Modified: 20 Apr 2025

    In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to calculate offsets and sizes for copy operations, which could result in heap overflow.

    Published: 16 Aug 2017
    4.7
    Medium

    CVE-2016-5855

    Last Modified: 20 Apr 2025

    In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a user-supplied buffer is casted to a structure without checking if the source buffer is large enough.

    Published: 16 Aug 2017
    4.7
    Medium

    CVE-2016-5858

    Last Modified: 20 Apr 2025

    In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.

    Published: 16 Aug 2017
    7
    High

    CVE-2016-5862

    Last Modified: 20 Apr 2025

    When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a device restart after kernel crash occurs.

    Published: 16 Aug 2017
    7.8
    High

    CVE-2016-5864

    Last Modified: 20 Apr 2025

    In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overflow. In another function, a missing check for a lower bound may result in an out of bounds memory access.

    Published: 16 Aug 2017
    4.7
    Medium

    CVE-2016-5347

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel stack data can be leaked to userspace by an audio driver.

    Published: 16 Aug 2017
    7
    High

    CVE-2016-5853

    Last Modified: 20 Apr 2025

    In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.

    Published: 16 Aug 2017
    4.7
    Medium

    CVE-2016-5854

    Last Modified: 20 Apr 2025

    In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.

    Published: 16 Aug 2017
    7
    High

    CVE-2016-5859

    Last Modified: 20 Apr 2025

    In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a buffer overflow.

    Published: 16 Aug 2017
    7
    High

    CVE-2016-5860

    Last Modified: 20 Apr 2025

    In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.

    Published: 16 Aug 2017
    7.8
    High

    CVE-2016-5863

    Last Modified: 20 Apr 2025

    In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.

    Published: 16 Aug 2017
    7
    High

    CVE-2016-5867

    Last Modified: 20 Apr 2025

    In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result in stack overflow.

    Published: 16 Aug 2017
    8.8
    High

    CVE-2017-6421

    Last Modified: 20 Apr 2025

    In the touch controller function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable may be controlled by the user and can lead to a buffer overflow.

    Published: 16 Aug 2017
    7.8
    High

    CVE-2017-8243

    Last Modified: 20 Apr 2025

    A buffer overflow can occur in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android when processing a firmware image file.

    Published: 16 Aug 2017
    9.8
    Critical

    CVE-2017-8248

    Last Modified: 20 Apr 2025

    A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.

    Published: 16 Aug 2017
    Unknown

    CVE-2017-12880

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-11424. Reason: This candidate is a duplicate of CVE-2017-11424. Notes: All CVE users should reference CVE-2017-11424 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Aug 2017
    7.8
    High

    CVE-2017-13686

    Last Modified: 20 Apr 2025

    net/ipv4/route.c in the Linux kernel 4.13-rc1 through 4.13-rc6 is too late to check for a NULL fi field when RTM_F_FIB_MATCH is set, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via crafted system calls. NOTE: this does not affect any stable release.

    Published: 16 Aug 2017
    8.8
    High

    CVE-2017-14164

    Last Modified: 20 Apr 2025

    A size-validation issue was discovered in opj_j2k_write_sot in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service (heap-based buffer overflow affecting opj_write_bytes_LE in lib/openjp2/cio.c) or possibly remote code execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14152.

    Published: 16 Aug 2017
    7.8
    High

    CVE-2017-8665

    Last Modified: 20 Apr 2025

    The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12862

    Last Modified: 20 Apr 2025

    In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12134

    Last Modified: 20 Apr 2025

    The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation.

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12863

    Last Modified: 20 Apr 2025

    In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12135

    Last Modified: 20 Apr 2025

    Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.

    Published: 15 Aug 2017
    7.8
    High

    CVE-2017-12136

    Last Modified: 20 Apr 2025

    Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling.

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12137

    Last Modified: 20 Apr 2025

    arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.

    Published: 15 Aug 2017
    7.5
    High

    CVE-2017-12852

    Last Modified: 20 Apr 2025

    The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

    Published: 15 Aug 2017
    8.8
    High

    CVE-2017-12864

    Last Modified: 20 Apr 2025

    In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

    Published: 15 Aug 2017
    9.8
    Critical

    CVE-2017-12791

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.

    Published: 15 Aug 2017
    6.5
    Medium

    CVE-2017-12855

    Last Modified: 20 Apr 2025

    Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant details while it is in use, whereas the guest is free to modify/reuse the grant entry when it is not in use. Under some circumstances, Xen will clear the status bits too early, incorrectly informing the guest that the grant is no longer in use. A guest may prematurely believe that a granted frame is safely private again, and reuse it in a way which contains sensitive information, while the domain on the far end of the grant is still using the grant. Xen 4.9, 4.8, 4.7, 4.6, and 4.5 are affected.

    Published: 15 Aug 2017
    5.9
    Medium

    CVE-2016-6029

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 116881.

    Published: 14 Aug 2017
    5.4
    Medium

    CVE-2016-6021

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116755.

    Published: 14 Aug 2017
    7.8
    High

    CVE-2017-1469

    Last Modified: 20 Apr 2025

    IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.

    Published: 14 Aug 2017