CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2017-1190

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to execute arbitrary code on the system. By manipulating a configurable property, an attacker could exploit this vulnerability to gain full control over the system. IBM X-Force ID: 123559.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-12426

    Last Modified: 20 Apr 2025

    GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-12853

    Last Modified: 20 Apr 2025

    The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-12850

    Last Modified: 20 Apr 2025

    An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affects kanboard before 1.0.46.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-12851

    Last Modified: 20 Apr 2025

    An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.46.

    Published: 14 Aug 2017
    7.8
    High

    CVE-2017-11156

    Last Modified: 20 Apr 2025

    Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.

    Published: 14 Aug 2017
    6.5
    Medium

    CVE-2017-11149

    Last Modified: 20 Apr 2025

    Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.

    Published: 14 Aug 2017
    7.8
    High

    CVE-2017-11150

    Last Modified: 20 Apr 2025

    Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the crafted file name of RTF documents.

    Published: 14 Aug 2017
    7.8
    High

    CVE-2017-9646

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file.

    Published: 14 Aug 2017
    7.8
    High

    CVE-2017-9648

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in Solar Controls WATTConfig M Software Version 2.5.10.1 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file.

    Published: 14 Aug 2017
    9.8
    Critical

    CVE-2017-9653

    Last Modified: 20 Apr 2025

    An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker is able to gain privileged access to the system while unauthorized.

    Published: 14 Aug 2017
    5.4
    Medium

    CVE-2017-9655

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrator for Microsoft Azure before 2016 R2 SP1, and PI Integrator for SAP HANA before 2017. An attacker may be able to upload a malicious script that attempts to redirect users to a malicious web site.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-9659

    Last Modified: 20 Apr 2025

    A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. The stack-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

    Published: 14 Aug 2017
    7
    High

    CVE-2017-9661

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the search path resulting in execution of arbitrary code.

    Published: 14 Aug 2017
    5.3
    Medium

    CVE-2017-9662

    Last Modified: 20 Apr 2025

    An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate privileges.

    Published: 14 Aug 2017
    8.8
    High

    CVE-2017-9660

    Last Modified: 20 Apr 2025

    A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.

    Published: 14 Aug 2017
    Unknown

    CVE-2017-12807

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12799. Reason: This candidate is a reservation duplicate of CVE-2017-12799. Notes: All CVE users should reference CVE-2017-12799 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Aug 2017
    6.1
    Medium

    CVE-2017-9802

    Last Modified: 20 Apr 2025

    The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function to parse input strings, which allows for XSS attacks by passing specially crafted input strings.

    Published: 14 Aug 2017
    7.5
    High

    CVE-2017-11185

    Last Modified: 4 Dec 2025

    The gmp plugin in strongSwan before 5.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted RSA signature.

    Published: 14 Aug 2017
    7.4
    High

    CVE-2014-8183

    Last Modified: 21 Nov 2024

    It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other organizations.

    Published: 14 Aug 2017
    7.5
    High

    CVE-2017-13710

    Last Modified: 20 Apr 2025

    The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a group section that is too small.

    Published: 14 Aug 2017
    5.5
    Medium

    CVE-2017-12982

    Last Modified: 20 Apr 2025

    The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocation failure) in the opj_image_create function in lib/openjp2/image.c, related to the opj_aligned_alloc_n function in opj_malloc.c.

    Published: 14 Aug 2017
    6.4
    Medium

    CVE-2017-7549

    Last Modified: 20 Apr 2025

    A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

    Published: 14 Aug 2017
    5.5
    Medium

    CVE-2017-18183

    Last Modified: 21 Nov 2024

    An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.

    Published: 12 Aug 2017
    7.5
    High

    CVE-2015-3614

    Last Modified: 20 Apr 2025

    Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.

    Published: 11 Aug 2017
    5.4
    Medium

    CVE-2015-3615

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving unspecified parameters and a privilege escalation attack.

    Published: 11 Aug 2017
    9.8
    Critical

    CVE-2015-3616

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands via unspecified parameters.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-6327

    Last Modified: 21 Apr 2026

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-6328

    Last Modified: 20 Apr 2025

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

    Published: 11 Aug 2017
    5.4
    Medium

    CVE-2017-9556

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Video Metadata Editor in Synology Video Station before 2.3.0-1435 allows remote authenticated attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11148

    Last Modified: 20 Apr 2025

    Server-side request forgery (SSRF) vulnerability in link preview in Synology Chat before 1.1.0-0806 allows remote authenticated users to access intranet resources via unspecified vectors.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11209

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability that occurs when reading a JPEG file embedded within XML Paper Specification (XPS) file. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11212

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to text output. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11214

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to rendering a path. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11219

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in the XFA rendering engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11220

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in an internal data structure. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11232

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability when processing Enhanced Metafile Format (EMF) data related to brush manipulation. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11238

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to curve drawing. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11243

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the XSLT engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11249

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when parsing an invalid Enhanced Metafile Format (EMF) record. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11260

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as a GIF image. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11261

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data and the embedded TIF image. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11268

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-11276

    Last Modified: 20 Apr 2025

    Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-11278

    Last Modified: 20 Apr 2025

    Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-11279

    Last Modified: 20 Apr 2025

    Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11259

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11210

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the font parsing, where the font is embedded in the XML Paper Specification (XPS) file. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-11236

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the internal handling of UTF-16 literal strings. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-3117

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the plugin that handles links within the PDF. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017