CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2017-6870

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2). The existing TLS protocol implementation could allow an attacker to read and modify data within a TLS session while performing a Man-in-the-Middle (MitM) attack.

    Published: 8 Aug 2017
    5.3
    Medium

    CVE-2017-7543

    Last Modified: 21 Nov 2024

    A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. The race was only triggered by an update, at which point an attacker could access exposed tenant VMs and network resources.

    Published: 8 Aug 2017
    5.9
    Medium

    CVE-2017-7781

    Last Modified: 21 Nov 2024

    An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result "POINT_AT_INFINITY" when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-7784

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-7803

    Last Modified: 25 Nov 2025

    When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    8.1
    High

    CVE-2017-9940

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with access to a low-privileged user account to read or write files on the file system of the SiPass integrated server over the network.

    Published: 8 Aug 2017
    7.8
    High

    CVE-2017-9942

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with local access to the SiPass integrated server or SiPass integrated client to potentially obtain credentials from the systems.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-6869

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens ViewPort for Web Office Portal before revision number 1453 that could allow an unauthenticated remote user to upload arbitrary code and execute it with the permissions of the operating-system user running the web server by sending specially crafted network packets to port 443/TCP or port 80/TCP.

    Published: 8 Aug 2017
    6.5
    Medium

    CVE-2017-6872

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker with access to port 21/tcp to access or alter historical measurement data stored on the device.

    Published: 8 Aug 2017
    7.4
    High

    CVE-2017-6873

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/tcp.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-7787

    Last Modified: 21 Nov 2024

    Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-7788

    Last Modified: 21 Nov 2024

    When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    5.3
    Medium

    CVE-2017-7789

    Last Modified: 21 Nov 2024

    If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    7.8
    High

    CVE-2017-7794

    Last Modified: 21 Nov 2024

    On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-7797

    Last Modified: 21 Nov 2024

    Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-7801

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-7806

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-9938

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Logon Remote Access service on port 16389/tcp to cause a Denial-of-Service condition. The service restarts automatically.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-9939

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker with network access to the SiPass integrated server to bypass the authentication mechanism and perform administrative operations.

    Published: 8 Aug 2017
    7.4
    High

    CVE-2017-9941

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SiPass integrated (All versions before V2.70) that could allow an attacker in a Man-in-the-Middle position between the SiPass integrated server and SiPass integrated clients to read or modify the network communication.

    Published: 8 Aug 2017
    7.4
    High

    CVE-2017-3085

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redirect.

    Published: 8 Aug 2017
    8.8
    High

    CVE-2017-3106

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Aug 2017
    5.4
    Medium

    CVE-2017-6871

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens SIMATIC WinCC Sm@rtClient for Android (All versions before V1.0.2.2) and SIMATIC WinCC Sm@rtClient for Android Lite (All versions before V1.0.2.2). An attacker with physical access to an unlocked mobile device, that has the affected app running, could bypass the app's authentication mechanism under certain conditions.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-7780

    Last Modified: 21 Nov 2024

    Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    7.5
    High

    CVE-2017-7783

    Last Modified: 21 Nov 2024

    If a long user name is used in a username/password combination in a site URL (such as " http://UserName:[email protected]"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    9.8
    Critical

    CVE-2017-7786

    Last Modified: 21 Nov 2024

    A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    5.3
    Medium

    CVE-2017-7791

    Last Modified: 25 Nov 2025

    On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

    Published: 8 Aug 2017
    6.1
    Medium

    CVE-2017-7799

    Last Modified: 21 Nov 2024

    JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but the vulnerability could possibly be used for a cross-site scripting (XSS) attack. This vulnerability affects Firefox < 55.

    Published: 8 Aug 2017
    6.5
    Medium

    CVE-2017-6866

    Last Modified: 20 Apr 2025

    A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the XHQ solution exceeding his configured permission level.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12664

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12662

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12663

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12666

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12665

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c.

    Published: 7 Aug 2017
    7.5
    High

    CVE-2017-12637

    Last Modified: 22 Apr 2026

    Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

    Published: 7 Aug 2017
    Unknown

    CVE-2017-6212

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requester. Further investigation showed that it was not a security issue. Notes: none

    Published: 7 Aug 2017
    7.5
    High

    CVE-2014-3462

    Last Modified: 20 Apr 2025

    The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".

    Published: 7 Aug 2017
    7.8
    High

    CVE-2015-5946

    Last Modified: 20 Apr 2025

    Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.

    Published: 7 Aug 2017
    7.8
    High

    CVE-2015-7571

    Last Modified: 20 Apr 2025

    Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

    Published: 7 Aug 2017
    7.5
    High

    CVE-2016-6220

    Last Modified: 20 Apr 2025

    Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.

    Published: 7 Aug 2017
    6.1
    Medium

    CVE-2017-12655

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.

    Published: 7 Aug 2017
    6.5
    Medium

    CVE-2017-12654

    Last Modified: 20 Apr 2025

    The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 7 Aug 2017
    7.8
    High

    CVE-2017-12653

    Last Modified: 20 Apr 2025

    360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.

    Published: 7 Aug 2017
    9.1
    Critical

    CVE-2015-1555

    Last Modified: 20 Apr 2025

    Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.

    Published: 7 Aug 2017
    5.5
    Medium

    CVE-2015-8621

    Last Modified: 20 Apr 2025

    t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2017-12651

    Last Modified: 20 Apr 2025

    Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.

    Published: 7 Aug 2017
    8.8
    High

    CVE-2014-9260

    Last Modified: 20 Apr 2025

    The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.

    Published: 7 Aug 2017
    8.2
    High

    CVE-2014-9262

    Last Modified: 20 Apr 2025

    The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

    Published: 7 Aug 2017
    7.5
    High

    CVE-2015-1378

    Last Modified: 20 Apr 2025

    cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users.

    Published: 7 Aug 2017
    5.5
    Medium

    CVE-2015-3839

    Last Modified: 20 Apr 2025

    The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).

    Published: 7 Aug 2017