CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-11267

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private data interpreted as JPEG data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11269

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) image stream data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-11271

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to transfer of pixel blocks. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-11277

    Last Modified: 20 Apr 2025

    Adobe Digital Editions 4.5.4 and earlier has an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-3091

    Last Modified: 20 Apr 2025

    Adobe Digital Editions 4.5.4 and earlier versions 4.5.4 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-3113

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable use after free vulnerability in JavaScript engine when creating large strings. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-3119

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in Acrobat/Reader 11.0.19 engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-3122

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data related to Bezier curves. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    8.8
    High

    CVE-2017-3123

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) data drawing position definition. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Aug 2017
    5.5
    Medium

    CVE-2017-8258

    Last Modified: 20 Apr 2025

    An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.

    Published: 11 Aug 2017
    7.8
    High

    CVE-2017-8264

    Last Modified: 20 Apr 2025

    A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products with Android releases from CAF using the Linux kernel.

    Published: 11 Aug 2017
    7.8
    High

    CVE-2017-8271

    Last Modified: 20 Apr 2025

    Out of bound memory write can happen in the MDSS Rotator driver in all Qualcomm products with Android releases from CAF using the Linux kernel by an unsanitized userspace-controlled parameter.

    Published: 11 Aug 2017
    7.8
    High

    CVE-2017-8273

    Last Modified: 20 Apr 2025

    In all Qualcomm products with Android release from CAF using the Linux kernel, while processing fastboot boot command when verified boot feature is disabled, with length greater than boot image buffer, a buffer overflow can occur.

    Published: 11 Aug 2017
    7.8
    High

    CVE-2017-8259

    Last Modified: 20 Apr 2025

    In the service locator in all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow can occur as the variable set for determining the size of the buffer is not used to indicate the size of the buffer.

    Published: 11 Aug 2017
    5.5
    Medium

    CVE-2017-8269

    Last Modified: 20 Apr 2025

    Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel can lead to exposure of kernel memory.

    Published: 11 Aug 2017
    Unknown

    CVE-2017-3168

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Aug 2017
    9.8
    Critical

    CVE-2017-8658

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability exists in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".

    Published: 11 Aug 2017
    8.3
    High

    CVE-2017-12839

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-bounds read) or possibly have unspecified other impact via a crafted mp3 file.

    Published: 11 Aug 2017
    6.5
    Medium

    CVE-2017-13062

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function formatIPTC in coders/meta.c, which allows attackers to cause a denial of service (WriteMETAImage memory consumption) via a crafted file.

    Published: 11 Aug 2017
    5.5
    Medium

    CVE-2017-18233

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIFF.cpp allows remote attackers to cause a denial of service (infinite loop) via crafted XMP data in a .avi file.

    Published: 11 Aug 2017
    7.5
    High

    CVE-2017-3130

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting FortiOS IKE VendorID packets.

    Published: 10 Aug 2017
    4.9
    Medium

    CVE-2017-7737

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.

    Published: 10 Aug 2017
    Unknown

    CVE-2008-1422

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1419. Reason: This candidate is a reservation duplicate of CVE-2008-1419. Notes: All CVE users should reference CVE-2008-1419 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Aug 2017
    Unknown

    CVE-2008-1421

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Aug 2017
    6.1
    Medium

    CVE-2017-12798

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-8518

    Last Modified: 20 Apr 2025

    Microsoft Edge allows a remote code execution vulnerability due to the way it accesses objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".

    Published: 10 Aug 2017
    8.8
    High

    CVE-2017-1174

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 123296.

    Published: 10 Aug 2017
    5.4
    Medium

    CVE-2017-1168

    Last Modified: 20 Apr 2025

    IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123187.

    Published: 10 Aug 2017
    8.2
    High

    CVE-2017-1192

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume memory resources. IBM X-Force ID: 123663.

    Published: 10 Aug 2017
    4.3
    Medium

    CVE-2017-1377

    Last Modified: 20 Apr 2025

    IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the system. IBM X-Force ID: 126874.

    Published: 10 Aug 2017
    5.4
    Medium

    CVE-2017-1431

    Last Modified: 20 Apr 2025

    IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 127632.

    Published: 10 Aug 2017
    5.5
    Medium

    CVE-2017-18261

    Last Modified: 21 Nov 2024

    The arch_timer_reg_read_stable macro in arch/arm64/include/asm/arch_timer.h in the Linux kernel before 4.13 allows local users to cause a denial of service (infinite recursion) by writing to a file under /sys/kernel/debug in certain circumstances, as demonstrated by a scenario involving debugfs, ftrace, PREEMPT_TRACER, and FUNCTION_GRAPH_TRACER.

    Published: 10 Aug 2017
    6.5
    Medium

    CVE-2017-12876

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in enhance.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

    Published: 10 Aug 2017
    7.8
    High

    CVE-2017-12799

    Last Modified: 20 Apr 2025

    The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-12805

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of service.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-12836

    Last Modified: 20 Apr 2025

    CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."

    Published: 10 Aug 2017
    6.5
    Medium

    CVE-2017-12877

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-7548

    Last Modified: 20 Apr 2025

    PostgreSQL versions before 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers with no privileges on a large object to overwrite the entire contents of the object, resulting in a denial of service.

    Published: 10 Aug 2017
    9.8
    Critical

    CVE-2017-9800

    Last Modified: 20 Apr 2025

    A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be generated by a malicious server, by a malicious user committing to a honest server (to attack another user of that server's repositories), or by a proxy server. The vulnerability affects all clients, including those that use file://, http://, and plain (untunneled) svn://.

    Published: 10 Aug 2017
    8.8
    High

    CVE-2017-1000117

    Last Modified: 20 Apr 2025

    A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-1000115

    Last Modified: 20 Apr 2025

    Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

    Published: 10 Aug 2017
    9.8
    Critical

    CVE-2017-1000116

    Last Modified: 20 Apr 2025

    Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

    Published: 10 Aug 2017
    6.5
    Medium

    CVE-2017-13058

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WritePCXImage in coders/pcx.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 10 Aug 2017
    6.5
    Medium

    CVE-2017-13059

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which allows attackers to cause a denial of service (WriteJNGImage memory consumption) via a crafted file.

    Published: 10 Aug 2017
    6.8
    Medium

    CVE-2017-3753

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.

    Published: 10 Aug 2017
    7.8
    High

    CVE-2017-3751

    Last Modified: 20 Apr 2025

    An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.

    Published: 10 Aug 2017
    9.8
    Critical

    CVE-2017-7546

    Last Modified: 20 Apr 2025

    PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

    Published: 10 Aug 2017
    8.8
    High

    CVE-2017-7547

    Last Modified: 20 Apr 2025

    PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.

    Published: 10 Aug 2017
    7.8
    High

    CVE-2017-1000111

    Last Modified: 20 Apr 2025

    Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.

    Published: 10 Aug 2017
    7
    High

    CVE-2017-1000112

    Last Modified: 20 Apr 2025

    Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.

    Published: 10 Aug 2017