CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-2885

    Last Modified: 21 Nov 2024

    An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.

    Published: 10 Aug 2017
    4.3
    Medium

    CVE-2017-7674

    Last Modified: 20 Apr 2025

    The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.

    Published: 10 Aug 2017
    7.5
    High

    CVE-2017-7675

    Last Modified: 20 Apr 2025

    The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.

    Published: 10 Aug 2017
    7.8
    High

    CVE-2017-0720

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0728

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (hevc decoder). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37469795.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0736

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38487564.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0745

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.

    Published: 9 Aug 2017
    8.2
    High

    CVE-2017-3752

    Last Modified: 20 Apr 2025

    An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter the routing tables of one or many routers, switches, or other devices that support OSPF within a routing domain.

    Published: 9 Aug 2017
    8.8
    High

    CVE-2017-9799

    Last Modified: 20 Apr 2025

    It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the worst case this could lead to secure credentials of the other user being compromised.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0713

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android libraries (sfntly). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-32096780.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0714

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0715

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36998372.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0716

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37203196.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0718

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0719

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0722

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0723

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37968755.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0724

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36819262.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0725

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0726

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36389123.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0727

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libgui). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-33004354.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0730

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (h264 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36279112.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0731

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0732

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37504237.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0733

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libmediaplayerservice). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38391487.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0734

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38014992.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0735

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-38239864.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0738

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563371.

    Published: 9 Aug 2017
    5.5
    Medium

    CVE-2017-0739

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37712181.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0740

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0741

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android ID: A-32458601. References: M-ALPS03007523.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0742

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0747

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel. Android ID: A-32524214. References: QC-CR#2044821.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0749

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. Android ID: A-36007735.

    Published: 9 Aug 2017
    6.1
    Medium

    CVE-2017-12777

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.

    Published: 9 Aug 2017
    7.2
    High

    CVE-2017-12756

    Last Modified: 20 Apr 2025

    Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter.

    Published: 9 Aug 2017
    9.8
    Critical

    CVE-2017-12774

    Last Modified: 20 Apr 2025

    finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0712

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207928.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0721

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37561455.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0729

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (mediadrmserver). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37710346.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0737

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37563942.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2017-0746

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.

    Published: 9 Aug 2017
    5.4
    Medium

    CVE-2017-1448

    Last Modified: 20 Apr 2025

    IBM Emptoris Supplier Lifecycle Management 10.0.x and 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 128173.

    Published: 9 Aug 2017
    9.8
    Critical

    CVE-2012-2780

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781.

    Published: 9 Aug 2017
    7.8
    High

    CVE-2015-2291

    Last Modified: 22 Apr 2026

    (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

    Published: 9 Aug 2017
    9.8
    Critical

    CVE-2015-0781

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.

    Published: 9 Aug 2017
    9.1
    Critical

    CVE-2015-2310

    Last Modified: 20 Apr 2025

    Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive information from memory via a crafted message, related to pointer validation.

    Published: 9 Aug 2017
    7.5
    High

    CVE-2015-2313

    Last Modified: 20 Apr 2025

    Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.2, when an application invokes the totalSize method on an object reader, allows remote peers to cause a denial of service (CPU consumption) via a crafted small message, which triggers a "tight" for loop. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-2312.

    Published: 9 Aug 2017
    5.9
    Medium

    CVE-2015-2674

    Last Modified: 20 Apr 2025

    Restkit allows man-in-the-middle attackers to spoof TLS servers by leveraging use of the ssl.wrap_socket function in Python with the default CERT_NONE value for the cert_reqs argument.

    Published: 9 Aug 2017
    9.8
    Critical

    CVE-2015-6816

    Last Modified: 20 Apr 2025

    ganglia-web before 3.7.1 allows remote attackers to bypass authentication.

    Published: 9 Aug 2017