CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-10817

    Last Modified: 20 Apr 2025

    MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to bypass authentication to alter settings in Relay Service Server.

    Published: 4 Aug 2017
    9.8
    Critical

    CVE-2017-10818

    Last Modified: 20 Apr 2025

    MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may allow an attacker to alter the connection settings of Terminal Agent and spoof the Relay Service.

    Published: 4 Aug 2017
    5.9
    Medium

    CVE-2017-10819

    Last Modified: 20 Apr 2025

    MaLion for Mac 4.3.0 to 5.2.1 does not properly validate certificates, which may allow an attacker to eavesdrop on an encrypted communication.

    Published: 4 Aug 2017
    7.8
    High

    CVE-2017-10820

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer of IP Messenger for Win 4.60 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 4 Aug 2017
    7.8
    High

    CVE-2017-2221

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 4 Aug 2017
    9.8
    Critical

    CVE-2017-10816

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the MaLion for Windows and Mac 5.0.0 to 5.2.1 allows remote attackers to execute arbitrary SQL commands via Relay Service Server.

    Published: 4 Aug 2017
    7.5
    High

    CVE-2017-10949

    Last Modified: 20 Apr 2025

    Directory Traversal in Dell Storage Manager 2016 R2.1 causes Information Disclosure when the doGet method of the EmWebsiteServlet class doesn't properly validate user provided path before using it in file operations. Was ZDI-CAN-4459.

    Published: 4 Aug 2017
    7.3
    High

    CVE-2017-11657

    Last Modified: 20 Apr 2025

    Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane directory.

    Published: 4 Aug 2017
    6.1
    Medium

    CVE-2017-12413

    Last Modified: 20 Apr 2025

    AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.

    Published: 4 Aug 2017
    7.5
    High

    CVE-2017-12428

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a denial of service in CloneDrawInfo in draw.c.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-12431

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a use-after-free vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a denial of service.

    Published: 4 Aug 2017
    9.8
    Critical

    CVE-2015-9107

    Last Modified: 20 Apr 2025

    Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't use a per-system key or even a salt; therefore, it's possible to create a universal decryptor.

    Published: 4 Aug 2017
    7.5
    High

    CVE-2017-12430

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-12427

    Last Modified: 20 Apr 2025

    The ProcessMSLScript function in coders/msl.c in ImageMagick before 6.9.9-5 and 7.x before 7.0.6-5 allows remote attackers to cause a denial of service (memory leak) via a crafted file, related to the WriteMSLImage function.

    Published: 4 Aug 2017
    7.5
    High

    CVE-2017-12429

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-12433

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadPESImage in coders/pes.c, which allows attackers to cause a denial of service, related to ResizeMagickMemory in memory.c.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-12434

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a missing NULL check vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service (assertion failure) in DestroyImageInfo in image.c.

    Published: 4 Aug 2017
    7.5
    High

    CVE-2017-12435

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-13060

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-13061

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-5, a length-validation vulnerability was found in the function ReadPSDLayersInternal in coders/psd.c, which allows attackers to cause a denial of service (ReadPSDImage memory exhaustion) via a crafted file.

    Published: 4 Aug 2017
    6.5
    Medium

    CVE-2017-12432

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadPCXImage in coders/pcx.c, which allows attackers to cause a denial of service.

    Published: 4 Aug 2017
    8.8
    High

    CVE-2017-11392

    Last Modified: 20 Apr 2025

    Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4745.

    Published: 3 Aug 2017
    8.8
    High

    CVE-2017-11391

    Last Modified: 20 Apr 2025

    Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "t" parameter within modTMCSS Proxy. Formerly ZDI-CAN-4744.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-11393

    Last Modified: 20 Apr 2025

    Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the tr parameter within Proxy.php. Formerly ZDI-CAN-4543.

    Published: 3 Aug 2017
    7.5
    High

    CVE-2017-11382

    Last Modified: 20 Apr 2025

    Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-11394

    Last Modified: 20 Apr 2025

    Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-4544.

    Published: 3 Aug 2017
    5.4
    Medium

    CVE-2017-1199

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 10.0, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123674.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-12414

    Last Modified: 20 Apr 2025

    Format Factory 4.1.0 has a DLL Hijacking Vulnerability because an untrusted search path is used for msimg32.dll, WindowsCodecs.dll, and dwmapi.dll.

    Published: 3 Aug 2017
    6.1
    Medium

    CVE-2017-1327

    Last Modified: 20 Apr 2025

    IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126062.

    Published: 3 Aug 2017
    6.5
    Medium

    CVE-2017-1504

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server version 9.0.0.4 could provide weaker than expected security after using the PasswordUtil command to enable AES password encryption. IBM X-Force ID: 129579.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-11105

    Last Modified: 20 Apr 2025

    The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.

    Published: 3 Aug 2017
    6.1
    Medium

    CVE-2017-11320

    Last Modified: 20 Apr 2025

    Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-11721

    Last Modified: 20 Apr 2025

    Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.

    Published: 3 Aug 2017
    8.8
    High

    CVE-2017-7442

    Last Modified: 20 Apr 2025

    Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

    Published: 3 Aug 2017
    7.5
    High

    CVE-2017-13711

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the sofree function in slirp/socket.c in QEMU (aka Quick Emulator) allows attackers to cause a denial of service (QEMU instance crash) by leveraging failure to properly clear ifq_so from pending packets.

    Published: 3 Aug 2017
    5.5
    Medium

    CVE-2017-14156

    Last Modified: 20 Apr 2025

    The atyfb_ioctl function in drivers/video/fbdev/aty/atyfb_base.c in the Linux kernel through 4.12.10 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading locations associated with padding bytes.

    Published: 3 Aug 2017
    7.5
    High

    CVE-2017-12418

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-5 has memory leaks in the parse8BIMW and format8BIM functions in coders/meta.c, related to the WriteImage function in MagickCore/constitute.c.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-12762

    Last Modified: 20 Apr 2025

    In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tree, and 4.4-stable tree.

    Published: 3 Aug 2017
    7.8
    High

    CVE-2017-1000418

    Last Modified: 21 Nov 2024

    The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 3 Aug 2017
    7
    High

    CVE-2017-7533

    Last Modified: 20 Apr 2025

    Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application that leverages simultaneous execution of the inotify_handle_event and vfs_rename functions.

    Published: 3 Aug 2017
    9.8
    Critical

    CVE-2017-11384

    Last Modified: 20 Apr 2025

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x3b21 due to lack of proper user input validation in mdHandlerLicenseManager.dll. Formerly ZDI-CAN-4561.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-11383

    Last Modified: 20 Apr 2025

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-11386

    Last Modified: 20 Apr 2025

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.

    Published: 2 Aug 2017
    7.5
    High

    CVE-2017-11387

    Last Modified: 20 Apr 2025

    Authentication Bypass in Trend Micro Control Manager 6.0 causes Information Disclosure when authentication validation is not done for functionality that can change debug logging level. Formerly ZDI-CAN-4512.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-11388

    Last Modified: 20 Apr 2025

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-11389

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Trend Micro Control Manager 6.0 allows remote code execution by attackers able to drop arbitrary files in a web-facing directory. Formerly ZDI-CAN-4684.

    Published: 2 Aug 2017
    7.5
    High

    CVE-2017-11390

    Last Modified: 20 Apr 2025

    XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-11385

    Last Modified: 20 Apr 2025

    SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x6b1b due to lack of proper user input validation in cmdHandlerStatusMonitor.dll. Formerly ZDI-CAN-4545.

    Published: 2 Aug 2017
    5.9
    Medium

    CVE-2015-3642

    Last Modified: 20 Apr 2025

    The TLS and DTLS processing functionality in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway devices with firmware 9.x before 9.3 Build 68.5, 10.0 through Build 78.6, 10.1 before Build 130.13, 10.1.e before Build 130.1302.e, 10.5 before Build 55.8, and 10.5.e before Build 55.8007.e makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

    Published: 2 Aug 2017
    7.8
    High

    CVE-2015-8264

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in F-Secure Online Scanner allows remote attackers to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as F-SecureOnlineScanner.exe.

    Published: 2 Aug 2017