CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-11670

    Last Modified: 20 Apr 2025

    A length validation (leading to out-of-bounds read and write) flaw was found in the way eapmd5pass 1.4 handled network traffic in the extract_eapusername function. A remote attacker could potentially use this flaw to crash the eapmd5pass process by generating specially crafted network traffic.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-11669

    Last Modified: 20 Apr 2025

    An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain circumstances by generating specially crafted network traffic.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2017-11760

    Last Modified: 20 Apr 2025

    uploadImage.php in ProjeQtOr before 6.3.2 allows remote authenticated users to execute arbitrary PHP code by uploading a .php file composed of concatenated image data and script data, as demonstrated by uploading as an image within the description text area.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-11757

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583. The overflow occurs after Server-Client encryption-key exchange. The issue results from an integer underflow that leads to a zero-byte allocation. The _srvLnaConnectMP1 function is affected.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11546

    Last Modified: 20 Apr 2025

    The insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mid file. NOTE: a crash might be relevant when using the --background option.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11548

    Last Modified: 20 Apr 2025

    The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11114

    Last Modified: 20 Apr 2025

    The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11115

    Last Modified: 20 Apr 2025

    The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted jpg file.

    Published: 31 Jul 2017
    7.8
    High

    CVE-2017-11116

    Last Modified: 20 Apr 2025

    The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11117

    Last Modified: 20 Apr 2025

    The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11118

    Last Modified: 20 Apr 2025

    The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted jpg file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11119

    Last Modified: 20 Apr 2025

    The chk_mem_access function in cpu/nes6502/nes6502.c in libnosefart.a in Nosefart 2.9-mls allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted nsf file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11547

    Last Modified: 20 Apr 2025

    The resample_gauss function in resample.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mid file. NOTE: a crash might be relevant when using the --background option. NOTE: the TiMidity++ README.alsaseq documentation suggests a setuid-root installation.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11550

    Last Modified: 20 Apr 2025

    The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11549

    Last Modified: 20 Apr 2025

    The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using the --background option.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11551

    Last Modified: 20 Apr 2025

    The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-11330

    Last Modified: 20 Apr 2025

    The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted avi file.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-11743

    Last Modified: 20 Apr 2025

    MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowledge of the hard-coded credential and the ability to communicate directly with the Mirth Connect management console may be able to intercept sensitive patient information. The admin account password is hard-coded as $K8t1ng throughout the application, and is the same across all installations. Customers do not have the option to change the Mirth Connect admin account password. The Mirth Connect admin account is created during the Connex install. The plaintext account password is hard-coded multiple times in the Connex install and update scripts.

    Published: 31 Jul 2017
    6.5
    Medium

    CVE-2017-9476

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.

    Published: 31 Jul 2017
    5.9
    Medium

    CVE-2017-9487

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to discover a WAN IPv6 IP address by leveraging knowledge of the CM MAC address.

    Published: 31 Jul 2017
    5.3
    Medium

    CVE-2017-9491

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC3941_2.5s3_PROD_sey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices does not set the secure flag for cookies in an https session to an administration application, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.

    Published: 31 Jul 2017
    6.3
    Medium

    CVE-2017-9493

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to conduct successful forced-pairing attacks (between an RF4CE remote and a set-top box) by repeatedly transmitting the same pairing code.

    Published: 31 Jul 2017
    5.9
    Medium

    CVE-2017-9475

    Last Modified: 20 Apr 2025

    Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address.

    Published: 31 Jul 2017
    6.5
    Medium

    CVE-2017-9477

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover the CM MAC address by connecting to the device's xfinitywifi hotspot.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-9479

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitrary commands as root by leveraging local network access and connecting to the syseventd server, as demonstrated by copying configuration data into a readable filesystem.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-9482

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root access to the Network Processor (NP) Linux system by enabling a TELNET daemon (through CVE-2017-9479 exploitation) and then establishing a TELNET session.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-9483

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows Network Processor (NP) Linux users to obtain root access to the Application Processor (AP) Linux system via shell metacharacters in commands.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9484

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover a CM MAC address by sniffing Wi-Fi traffic and performing simple arithmetic calculations.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9485

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to write arbitrary data to a known /var/tmp/sess_* pathname by leveraging the device's operation in UI dev mode.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9486

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to compute password-of-the-day values via unspecified vectors.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2017-9489

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2017-9490

    Last Modified: 20 Apr 2025

    The Comcast firmware on Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows configuration changes via CSRF.

    Published: 31 Jul 2017
    4.6
    Medium

    CVE-2017-9495

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web Inspector script.

    Published: 31 Jul 2017
    6.8
    Medium

    CVE-2017-9496

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to access an SNMP server by connecting a cable to the Ethernet port, and then establishing communication with the device's link-local IPv6 address.

    Published: 31 Jul 2017
    6.8
    Medium

    CVE-2017-9497

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-9498

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9478

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices sets the CM MAC address to a value with a two-byte offset from the MTA/VoIP MAC address, which indirectly allows remote attackers to discover hidden Home Security Wi-Fi networks by leveraging the embedding of the MTA/VoIP MAC address into the DNS hostname.

    Published: 31 Jul 2017
    5.5
    Medium

    CVE-2017-9480

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows local users (e.g., users who have command access as a consequence of CVE-2017-9479 exploitation) to read arbitrary files via UPnP access to /var/IGD/.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9481

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain unintended access to the Network Processor (NP) 169.254/16 IP network by adding a routing-table entry that specifies the LAN IP address as the router for that network.

    Published: 31 Jul 2017
    8.8
    High

    CVE-2017-9488

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 address and then entering unspecified hardcoded credentials. This wan0 interface cannot be accessed from the public Internet.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9492

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC3941_2.5s3_PROD_sey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices does not include the HTTPOnly flag in a Set-Cookie header for administration applications, which makes it easier for remote attackers to obtain potentially sensitive information via script access to cookies.

    Published: 31 Jul 2017
    5.3
    Medium

    CVE-2017-9494

    Last Modified: 20 Apr 2025

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-9521

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC3941_2.5s3_PROD_sey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices allows remote attackers to execute arbitrary code via a specific (but unstated) exposed service. NOTE: the scope of this CVE does NOT include the concept of "Unnecessary Services" in general; the scope is only a single service that is unnecessarily exposed, leading to remote code execution. The details of that service might be disclosed at a later date.

    Published: 31 Jul 2017
    7.5
    High

    CVE-2017-9522

    Last Modified: 20 Apr 2025

    The Time Warner firmware on Technicolor TC8717T devices sets the default Wi-Fi passphrase to a combination of the SSID and BSSID, which makes it easier for remote attackers to obtain network access by reading a beacon frame.

    Published: 31 Jul 2017
    Unknown

    CVE-2017-12073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.

    Published: 31 Jul 2017
    9.8
    Critical

    CVE-2017-7551

    Last Modified: 20 Apr 2025

    389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.

    Published: 31 Jul 2017
    7
    High

    CVE-2017-11756

    Last Modified: 20 Apr 2025

    In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.

    Published: 30 Jul 2017
    7.5
    High

    CVE-2017-11746

    Last Modified: 20 Apr 2025

    Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command.

    Published: 30 Jul 2017
    7.8
    High

    CVE-2017-11749

    Last Modified: 20 Apr 2025

    InternetSoft FTP Commander 8.02 and prior has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll file.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11747

    Last Modified: 20 Apr 2025

    main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tinyproxy.pid modification before a root script executes a "kill `cat /run/tinyproxy/tinyproxy.pid`" command.

    Published: 30 Jul 2017