CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-11748

    Last Modified: 20 Apr 2025

    VIT Spider Player 2.5.3 has an untrusted search path, allowing DLL hijacking via a Trojan horse dwmapi.dll, olepro32.dll, dsound.dll, or AUDIOSES.dll file.

    Published: 30 Jul 2017
    6.1
    Medium

    CVE-2017-11744

    Last Modified: 20 Apr 2025

    In MODX Revolution 2.5.7, the "key" and "name" parameters in the System Settings module are vulnerable to XSS. A malicious payload sent to connectors/index.php will be triggered by every user, when they visit this module.

    Published: 30 Jul 2017
    7.8
    High

    CVE-2017-11742

    Last Modified: 20 Apr 2025

    The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on Windows allows local users to gain privileges via a Trojan horse ADVAPI32.DLL in the current working directory because of an untrusted search path, aka DLL hijacking.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11359

    Last Modified: 20 Apr 2025

    The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11331

    Last Modified: 20 Apr 2025

    The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11332

    Last Modified: 20 Apr 2025

    The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11333

    Last Modified: 20 Apr 2025

    The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.

    Published: 30 Jul 2017
    5.5
    Medium

    CVE-2017-11358

    Last Modified: 20 Apr 2025

    The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.

    Published: 30 Jul 2017
    3.3
    Low

    CVE-2017-11735

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in the originally named product. Notes: none

    Published: 30 Jul 2017
    6.5
    Medium

    CVE-2017-11750

    Last Modified: 20 Apr 2025

    The ReadOneJNGImage function in coders/png.c in ImageMagick 6.9.9-4 and 7.0.6-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 30 Jul 2017
    6.5
    Medium

    CVE-2017-11751

    Last Modified: 20 Apr 2025

    The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 30 Jul 2017
    6.5
    Medium

    CVE-2017-11755

    Last Modified: 20 Apr 2025

    The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.

    Published: 30 Jul 2017
    8.8
    High

    CVE-2017-11736

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via the tags array parameter.

    Published: 29 Jul 2017
    6.1
    Medium

    CVE-2017-11737

    Last Modified: 20 Apr 2025

    interface/js/app/history.js in WebUI in Rspamd before 1.6.3 allows XSS via the Subject and Message-Id headers, which are mishandled in the history page.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11732

    Last Modified: 20 Apr 2025

    A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    5.4
    Medium

    CVE-2017-11725

    Last Modified: 20 Apr 2025

    The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11728

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was found in the function OpCode (called from decompileSETMEMBER) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11731

    Last Modified: 20 Apr 2025

    An invalid memory read vulnerability was found in the function OpCode (called from isLogicalOp and decompileIF) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11733

    Last Modified: 20 Apr 2025

    A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    7.5
    High

    CVE-2017-11723

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in plugins/ImageManager/backend.php in Xinha 0.96, as used in Jojo 4.4.0, allows remote attackers to delete any folder via directory traversal sequences in the deld parameter.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11729

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1440) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11730

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was found in the function OpCode (called from decompileINCR_DECR line 1474) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    5.5
    Medium

    CVE-2017-11734

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was found in the function decompileCALLFUNCTION in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 29 Jul 2017
    6.5
    Medium

    CVE-2017-11754

    Last Modified: 20 Apr 2025

    The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.

    Published: 29 Jul 2017
    6.5
    Medium

    CVE-2017-11753

    Last Modified: 20 Apr 2025

    The GetImageDepth function in MagickCore/attribute.c in ImageMagick 7.0.6-4 might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted Flexible Image Transport System (FITS) file.

    Published: 29 Jul 2017
    6.5
    Medium

    CVE-2017-11752

    Last Modified: 20 Apr 2025

    The ReadMAGICKImage function in coders/magick.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 29 Jul 2017
    7.8
    High

    CVE-2017-12596

    Last Modified: 20 Apr 2025

    In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.

    Published: 29 Jul 2017
    9
    Critical

    CVE-2017-4919

    Last Modified: 20 Apr 2025

    VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate.

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6251

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a missing permissions check may allow users to gain access to arbitrary physical system memory, which may lead to an escalation of privileges.

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6252

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to a denial of service or potential escalation of privileges.

    Published: 28 Jul 2017
    6.1
    Medium

    CVE-2017-6259

    Last Modified: 20 Apr 2025

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect detection and recovery from an invalid state produced by specific user actions may lead to denial of service.

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6253

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated which may lead to denial of service or potential escalation of privileges

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6254

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from an user to the driver is used without validation which may lead to denial of service or potential escalation of privileges.

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6255

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.

    Published: 28 Jul 2017
    7.8
    High

    CVE-2017-6256

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or potential escalation of privileges.

    Published: 28 Jul 2017
    8.8
    High

    CVE-2017-6257

    Last Modified: 20 Apr 2025

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges

    Published: 28 Jul 2017
    6.5
    Medium

    CVE-2017-6260

    Last Modified: 20 Apr 2025

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect calculation of string length may lead to denial of service.

    Published: 28 Jul 2017
    9.1
    Critical

    CVE-2017-11693

    Last Modified: 20 Apr 2025

    MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. PostgreSQL is used as the Document Management System database. The account name is dms. The password is hard-coded throughout the application, and is the same across all installations. Customers do not have the option to change passwords. The dms account for PostgreSQL has access to the database schema for Document Management System.

    Published: 28 Jul 2017
    9.1
    Critical

    CVE-2017-11694

    Last Modified: 20 Apr 2025

    MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sensitive patient and financial information. The Apache Solr account name is dms. The password is hard-coded throughout the application, and is the same across all installations. Customers do not have the option to change passwords. The dms account for Apache Solr has access to all indexed patient documents.

    Published: 28 Jul 2017
    6.5
    Medium

    CVE-2017-11722

    Last Modified: 20 Apr 2025

    The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.

    Published: 28 Jul 2017
    9.8
    Critical

    CVE-2017-11645

    Last Modified: 20 Apr 2025

    NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html.

    Published: 28 Jul 2017
    4.9
    Medium

    CVE-2017-11183

    Last Modified: 20 Apr 2025

    front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.

    Published: 28 Jul 2017
    9.8
    Critical

    CVE-2017-11184

    Last Modified: 20 Apr 2025

    SQL injection exists in front/devicesoundcard.php in GLPI before 9.1.5 via the start parameter.

    Published: 28 Jul 2017
    5.4
    Medium

    CVE-2017-11647

    Last Modified: 20 Apr 2025

    NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site scripting attacks. Creating an SSID with an XSS payload results in successful exploitation.

    Published: 28 Jul 2017
    6.5
    Medium

    CVE-2017-11703

    Last Modified: 20 Apr 2025

    A memory leak vulnerability was found in the function parseSWF_DOACTION in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 28 Jul 2017
    6.5
    Medium

    CVE-2017-11704

    Last Modified: 20 Apr 2025

    A heap-based buffer over-read was found in the function decompileIF in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 28 Jul 2017
    6.5
    Medium

    CVE-2017-11705

    Last Modified: 20 Apr 2025

    A memory leak was found in the function parseSWF_SHAPEWITHSTYLE in util/parser.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

    Published: 28 Jul 2017
    7.5
    High

    CVE-2017-11706

    Last Modified: 20 Apr 2025

    The Boozt Fashion application before 2.3.4 for Android allows remote attackers to read login credentials by sniffing the network and leveraging the lack of SSL. NOTE: the vendor response, before the application was changed to enable SSL logins, was "At the moment that is an accepted risk. We only have https on the checkout part of the site."

    Published: 28 Jul 2017
    9.8
    Critical

    CVE-2017-11715

    Last Modified: 20 Apr 2025

    job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related extensions, which might allow remote authenticated admins to execute arbitrary PHP code by uploading a .phtml file after certain actions involving admin/system/safe.php and job/cv.php.

    Published: 28 Jul 2017
    6.1
    Medium

    CVE-2017-11716

    Last Modified: 20 Apr 2025

    MetInfo through 5.3.17 allows stored XSS via HTML Edit Mode.

    Published: 28 Jul 2017