CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-12199

    Last Modified: 20 Apr 2025

    The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, and tags_update_order tag-list-item.

    Published: 2 Aug 2017
    9.8
    Critical

    CVE-2017-12588

    Last Modified: 20 Apr 2025

    The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.

    Published: 2 Aug 2017
    6.5
    Medium

    CVE-2017-2664

    Last Modified: 21 Nov 2024

    CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1 lacks RBAC controls on certain methods in the rails application portion of CloudForms. An attacker with access could use a variety of methods within the rails application portion of CloudForms to escalate privileges.

    Published: 2 Aug 2017
    7.5
    High

    CVE-2017-12425

    Last Modified: 20 Apr 2025

    An issue was discovered in Varnish HTTP Cache 4.0.1 through 4.0.4, 4.1.0 through 4.1.7, 5.0.0, and 5.1.0 through 5.1.2. A wrong if statement in the varnishd source code means that particular invalid requests from the client can trigger an assert, related to an Integer Overflow. This causes the varnishd worker process to abort and restart, losing the cached contents in the process. An attacker can therefore crash the varnishd worker process on demand and effectively keep it from serving content - a Denial-of-Service attack. The specific source-code filename containing the incorrect statement varies across releases.

    Published: 2 Aug 2017
    8.8
    High

    CVE-2017-7530

    Last Modified: 21 Nov 2024

    In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing when invoking arbitrary methods via filtering on VMs that MiqExpression will execute that is triggerable by API users. An attacker could use this to execute actions they should not be allowed to (e.g. destroying VMs).

    Published: 2 Aug 2017
    5.5
    Medium

    CVE-2017-8572

    Last Modified: 20 Apr 2025

    Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows an information disclosure vulnerability due to the way that it discloses the contents of its memory, aka "Microsoft Office Outlook Information Disclosure Vulnerability".

    Published: 1 Aug 2017
    7.8
    High

    CVE-2017-8663

    Last Modified: 20 Apr 2025

    Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a remote code execution vulnerability due to the way Microsoft Outlook parses specially crafted email messages, aka "Microsoft Office Outlook Memory Corruption Vulnerability"

    Published: 1 Aug 2017
    7.8
    High

    CVE-2017-8571

    Last Modified: 20 Apr 2025

    Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a security feature bypass vulnerability due to the way that it handles input, aka "Microsoft Office Outlook Security Feature Bypass Vulnerability".

    Published: 1 Aug 2017
    6.1
    Medium

    CVE-2017-1500

    Last Modified: 20 Apr 2025

    A Reflected Cross Site Scripting (XSS) vulnerability exists in the authorization function exposed by RESTful Web Api of IBM Worklight Framework 6.1, 6.2, 6.3, 7.0, 7.1, and 8.0. The vulnerable parameter is "scope"; if you set as its value a "realm" not defined in authenticationConfig.xml, you get an HTTP 403 Forbidden response and the value will be reflected in the body of the HTTP response. By setting it to arbitrary JavaScript code it is possible to modify the flow of the authorization function, potentially leading to credential disclosure within a trusted session.

    Published: 1 Aug 2017
    6.5
    Medium

    CVE-2017-4922

    Last Modified: 20 Apr 2025

    VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure issue due to the service startup script using world writable directories as temporary storage for critical information. Successful exploitation of this issue may allow unprivileged host users to access certain critical information when the service gets restarted.

    Published: 1 Aug 2017
    8.8
    High

    CVE-2017-4921

    Last Modified: 20 Apr 2025

    VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library that may lead to privilege escalation.

    Published: 1 Aug 2017
    9.8
    Critical

    CVE-2017-4923

    Last Modified: 20 Apr 2025

    VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability. This issue may allow plaintext credentials to be obtained when using the vCenter Server Appliance file-based backup feature.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-11379

    Last Modified: 20 Apr 2025

    Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.

    Published: 1 Aug 2017
    9.8
    Critical

    CVE-2017-11380

    Last Modified: 20 Apr 2025

    Backup archives were found to be encrypted with a static password across different installations, which suggest the same password may be used in all virtual appliance instances of Trend Micro Deep Discovery Director 1.1.

    Published: 1 Aug 2017
    9.8
    Critical

    CVE-2017-11381

    Last Modified: 20 Apr 2025

    A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.

    Published: 1 Aug 2017
    6.1
    Medium

    CVE-2017-12062

    Last Modified: 20 Apr 2025

    An XSS issue was discovered in manage_user_page.php in MantisBT 2.x before 2.5.2. The 'filter' field is not sanitized before being rendered in the Manage User page, allowing remote attackers to execute arbitrary JavaScript code if CSP is disabled.

    Published: 1 Aug 2017
    6.1
    Medium

    CVE-2017-12061

    Last Modified: 20 Apr 2025

    An XSS issue was discovered in admin/install.php in MantisBT before 1.3.12 and 2.x before 2.5.2. Some variables under user control in the MantisBT installation script are not properly sanitized before being output, allowing remote attackers to inject arbitrary JavaScript code, as demonstrated by the $f_database, $f_db_username, and $f_admin_username variables. This is mitigated by the fact that the admin/ folder should be deleted after installation, and also prevented by CSP.

    Published: 1 Aug 2017
    8.1
    High

    CVE-2017-11130

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The product's protocol only tries to ensure confidentiality. In the whole protocol, no integrity or authenticity checks are done. Therefore man-in-the-middle attackers can conduct replay attacks.

    Published: 1 Aug 2017
    6.5
    Medium

    CVE-2017-11136

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. It uses RSA to exchange a secret for symmetric encryption of messages. However, the private RSA key is not only stored on the client but transmitted to the backend, too. Moreover, the key to decrypt the private key is composed of the first 32 bytes of the SHA-512 hash of the user password. But this hash is stored on the backend, too. Therefore, everyone with access to the backend database can read the transmitted secret for symmetric encryption, hence can read the communication.

    Published: 1 Aug 2017
    5.3
    Medium

    CVE-2015-5059

    Last Modified: 20 Apr 2025

    The "Project Documentation" feature in MantisBT 1.2.19 and earlier, when the threshold to access files ($g_view_proj_doc_threshold) is set to ANYBODY, allows remote authenticated users to download attachments linked to arbitrary private projects via a file id number in the file_id parameter to file_download.php.

    Published: 1 Aug 2017
    9.8
    Critical

    CVE-2017-11129

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The keystore is locked with a hard-coded password. Therefore, everyone with access to the keystore can read the content out, for example the private key of the user.

    Published: 1 Aug 2017
    5.9
    Medium

    CVE-2017-11131

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. For authentication, the user password is hashed directly with SHA-512 without a salt or another key-derivation mechanism to enable a secure secret for authentication. Moreover, only the first 32 bytes of the hash are used. This allows for easy dictionary and rainbow-table attacks if an attacker has access to the password hash.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-11132

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat before 1.5.18 for Android. No certificate pinning is implemented; therefore the attacker could issue a certificate for the backend and the application would not notice it.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-11133

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. To encrypt messages, AES in CBC mode is used with a pseudo-random secret. This secret and the IV are generated with math.random() in previous versions and with CryptoJS.lib.WordArray.random() in newer versions, which uses math.random() internally. This is not cryptographically strong.

    Published: 1 Aug 2017
    6.5
    Medium

    CVE-2017-11134

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android. The login credentials are written into a log file on the device. Hence, an attacker with access to the logs can read them.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-11135

    Last Modified: 20 Apr 2025

    An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only needs to know the device ID. This causes a denial of service. This might be interpreted as a vulnerability in customer-controlled software, in the sense that the StashCat client side has no secure way to signal that it is ending a session and that data should be deleted.

    Published: 1 Aug 2017
    6.5
    Medium

    CVE-2017-11552

    Last Modified: 20 Apr 2025

    mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.

    Published: 1 Aug 2017
    6.1
    Medium

    CVE-2017-12068

    Last Modified: 20 Apr 2025

    The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-12064

    Last Modified: 20 Apr 2025

    The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions via a crafted name.

    Published: 1 Aug 2017
    9.8
    Critical

    CVE-2017-12065

    Last Modified: 20 Apr 2025

    spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.

    Published: 1 Aug 2017
    5.4
    Medium

    CVE-2017-12066

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable. NOTE: this vulnerability exists because of an incomplete fix (lack of the htmlspecialchars ENT_QUOTES flag) for CVE-2017-11163.

    Published: 1 Aug 2017
    7.5
    High

    CVE-2017-12067

    Last Modified: 20 Apr 2025

    Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.

    Published: 1 Aug 2017
    6.1
    Medium

    CVE-2017-12131

    Last Modified: 20 Apr 2025

    The Easy Testimonials plugin 3.0.4 for WordPress has XSS in include/settings/display.options.php, as demonstrated by the Default Testimonials Width, View More Testimonials Link, and Testimonial Excerpt Options screens.

    Published: 1 Aug 2017
    8.8
    High

    CVE-2017-11726

    Last Modified: 20 Apr 2025

    services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by changing an e-mail address setting.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2017-11648

    Last Modified: 20 Apr 2025

    Techroutes TR 1803-3G Wireless Cellular Router/Modem 2.4.25 devices do not possess any protection against a CSRF vulnerability, as demonstrated by a goform/BasicSettings request to disable port filtering.

    Published: 31 Jul 2017
    6.1
    Medium

    CVE-2017-11727

    Last Modified: 20 Apr 2025

    services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a ContactCommon field) on victims who click on a crafted link, aka XSS.

    Published: 31 Jul 2017
    6.1
    Medium

    CVE-2017-1303

    Last Modified: 4 Dec 2025

    IBM WebSphere Portal and Web Content Manager 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125457.

    Published: 31 Jul 2017
    5.4
    Medium

    CVE-2016-9715

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119728.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2016-9716

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119729.

    Published: 31 Jul 2017
    5.7
    Medium

    CVE-2016-9719

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 119733.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2016-9714

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 119727.

    Published: 31 Jul 2017
    6.5
    Medium

    CVE-2016-9717

    Last Modified: 20 Apr 2025

    HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables attackers by exposing the presence of duplicated parameters which may produce an anomalous behavior in the application that can be potentially exploited.

    Published: 31 Jul 2017
    5.4
    Medium

    CVE-2016-9718

    Last Modified: 20 Apr 2025

    IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 119732.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-1227

    Last Modified: 20 Apr 2025

    IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.

    Published: 31 Jul 2017
    6.1
    Medium

    CVE-2017-1332

    Last Modified: 20 Apr 2025

    IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126234.

    Published: 31 Jul 2017
    4.9
    Medium

    CVE-2017-1370

    Last Modified: 20 Apr 2025

    IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863.

    Published: 31 Jul 2017
    5.9
    Medium

    CVE-2017-1386

    Last Modified: 20 Apr 2025

    IBM API Connect 5.0.0.0 could allow a user to bypass policy restrictions and create non-compliant passwords which could be intercepted and decrypted using man in the middle techniques. IBM X-Force ID: 127160.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-1460

    Last Modified: 20 Apr 2025

    IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead to loss of connectivity. IBM X-Force ID: 128379.

    Published: 31 Jul 2017
    5.4
    Medium

    CVE-2017-1496

    Last Modified: 20 Apr 2025

    IBM Sterling B2B Integrator Standard Edition 5.2.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128694.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-11668

    Last Modified: 20 Apr 2025

    An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:134 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by generating specially crafted network traffic.

    Published: 31 Jul 2017