CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-11683

    Last Modified: 20 Apr 2025

    There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.

    Published: 26 Jul 2017
    5.5
    Medium

    CVE-2017-9260

    Last Modified: 20 Apr 2025

    The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.

    Published: 26 Jul 2017
    6.5
    Medium

    CVE-2017-11613

    Last Modified: 20 Apr 2025

    In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is called based on td_imagelength. If we set the value of td_imagelength close to the amount of system memory, it will hang the system or trigger the OOM killer.

    Published: 26 Jul 2017
    6.5
    Medium

    CVE-2017-11640

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/tiff.c.

    Published: 26 Jul 2017
    6.5
    Medium

    CVE-2017-11644

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadMATImage() function in coders/mat.c.

    Published: 26 Jul 2017
    7.8
    High

    CVE-2017-12449

    Last Modified: 20 Apr 2025

    The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.

    Published: 26 Jul 2017
    7.8
    High

    CVE-2017-12455

    Last Modified: 20 Apr 2025

    The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.

    Published: 26 Jul 2017
    7.8
    High

    CVE-2017-12457

    Last Modified: 20 Apr 2025

    The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.

    Published: 26 Jul 2017
    7.8
    High

    CVE-2017-12458

    Last Modified: 20 Apr 2025

    The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.

    Published: 26 Jul 2017
    7.8
    High

    CVE-2017-12459

    Last Modified: 20 Apr 2025

    The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.

    Published: 26 Jul 2017
    5.5
    Medium

    CVE-2017-9259

    Last Modified: 20 Apr 2025

    The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted wav file.

    Published: 26 Jul 2017
    8.8
    High

    CVE-2017-9614

    Last Modified: 20 Apr 2025

    The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse of the libjpeg API

    Published: 26 Jul 2017
    6.5
    Medium

    CVE-2017-11639

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h.

    Published: 26 Jul 2017
    5.5
    Medium

    CVE-2017-9258

    Last Modified: 20 Apr 2025

    The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.

    Published: 26 Jul 2017
    6.1
    Medium

    CVE-2016-6133

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.aspx.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2017-6672

    Last Modified: 20 Apr 2025

    A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affected device. More Information: CSCvb99022 CSCvc16964 CSCvc37351 CSCvc54843 CSCvc63444 CSCvc77815 CSCvc88658 CSCve08955 CSCve14141 CSCve33870.

    Published: 25 Jul 2017
    7.2
    High

    CVE-2017-6746

    Last Modified: 20 Apr 2025

    A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid administrator credentials. Affected Products: Cisco AsyncOS Software 10.0 and later for WSA on both virtual and hardware appliances. More Information: CSCvd88862. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270 10.1.1-235.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-6753

    Last Modified: 20 Apr 2025

    A vulnerability in Cisco WebEx browser extensions for Google Chrome and Mozilla Firefox could allow an unauthenticated, remote attacker to execute arbitrary code with the privileges of the affected browser on an affected system. This vulnerability affects the browser extensions for Cisco WebEx Meetings Server, Cisco WebEx Centers (Meeting Center, Event Center, Training Center, and Support Center), and Cisco WebEx Meetings when they are running on Microsoft Windows. The vulnerability is due to a design defect in the extension. An attacker who can convince an affected user to visit an attacker-controlled web page or follow an attacker-supplied link with an affected browser could exploit the vulnerability. If successful, the attacker could execute arbitrary code with the privileges of the affected browser. The following versions of the Cisco WebEx browser extensions are affected: Versions prior to 1.0.12 of the Cisco WebEx extension on Google Chrome, Versions prior to 1.0.12 of the Cisco WebEx extension on Mozilla Firefox. Cisco Bug IDs: CSCvf15012 CSCvf15020 CSCvf15030 CSCvf15033 CSCvf15036 CSCvf15037.

    Published: 25 Jul 2017
    8.6
    High

    CVE-2017-6612

    Last Modified: 20 Apr 2025

    A vulnerability in the gateway GPRS support node (GGSN) of Cisco ASR 5000 Series Aggregation Services Routers 17.3.9.62033 through 21.1.2 could allow an unauthenticated, remote attacker to redirect HTTP traffic sent to an affected device. More Information: CSCvc67927.

    Published: 25 Jul 2017
    6.7
    Medium

    CVE-2017-6748

    Last Modified: 20 Apr 2025

    A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-level credentials. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88855. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270 10.1.1-234.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2017-6751

    Last Modified: 20 Apr 2025

    A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward traffic from the web proxy interface of an affected device to the administrative management interface of an affected device, aka an Access Control Bypass Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88863. Known Affected Releases: 10.1.0-204 9.0.0-485.

    Published: 25 Jul 2017
    5.4
    Medium

    CVE-2017-6749

    Last Modified: 20 Apr 2025

    A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCvd88865. Known Affected Releases: 10.1.0-204.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2017-6750

    Last Modified: 20 Apr 2025

    A vulnerability in AsyncOS for the Cisco Web Security Appliance (WSA) could allow an unauthenticated, local attacker to log in to the device with the privileges of a limited user or an unauthenticated, remote attacker to authenticate to certain areas of the web GUI, aka a Static Credentials Vulnerability. Affected Products: virtual and hardware versions of Cisco Web Security Appliance (WSA). More Information: CSCve06124. Known Affected Releases: 10.1.0-204. Known Fixed Releases: 10.5.1-270.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2017-6755

    Last Modified: 20 Apr 2025

    A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning (PCP) Tool could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc90312. Known Affected Releases: 12.1.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2015-0674

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2015-4463

    Last Modified: 20 Apr 2025

    The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2016-10401

    Last Modified: 20 Apr 2025

    ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-11457

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request, aka SAP Security Note 2387249.

    Published: 25 Jul 2017
    9.8
    Critical

    CVE-2017-11459

    Last Modified: 20 Apr 2025

    SAP TREX 7.10 allows remote attackers to (1) read arbitrary files via an fget command or (2) write to arbitrary files and consequently execute arbitrary code via an fdir command, aka SAP Security Note 2419592.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2017-11460

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2017-11458

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ctcprotocol/Protocol servlet in SAP NetWeaver AS JAVA 7.3 allows remote attackers to inject arbitrary web script or HTML via the sessionID parameter, aka SAP Security Note 2406783.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2015-1417

    Last Modified: 20 Apr 2025

    The inet module in FreeBSD 10.2x before 10.2-PRERELEASE, 10.2-BETA2-p2, 10.2-RC1-p1, 10.1x before 10.1-RELEASE-p16, 9.x before 9.3-STABLE, 9.3-RELEASE-p21, and 8.x before 8.4-STABLE, 8.4-RELEASE-p35 on systems with VNET enabled and at least 16 VNET instances allows remote attackers to cause a denial of service (mbuf consumption) via multiple concurrent TCP connections.

    Published: 25 Jul 2017
    7.8
    High

    CVE-2015-1438

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in Panda Security Kernel Memory Access Driver 1.0.0.13 allows attackers to execute arbitrary code with kernel privileges via a crafted size input for allocated kernel paged pool and allocated non-paged pool buffers.

    Published: 25 Jul 2017
    5.9
    Medium

    CVE-2015-0904

    Last Modified: 20 Apr 2025

    The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2015-1332

    Last Modified: 20 Apr 2025

    The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted website.

    Published: 25 Jul 2017
    9.8
    Critical

    CVE-2015-2798

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2015-4462

    Last Modified: 20 Apr 2025

    Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2015-5594

    Last Modified: 20 Apr 2025

    The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.

    Published: 25 Jul 2017
    7.8
    High

    CVE-2015-6585

    Last Modified: 20 Apr 2025

    hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2015-8013

    Last Modified: 20 Apr 2025

    s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.

    Published: 25 Jul 2017
    6.5
    Medium

    CVE-2017-8919

    Last Modified: 20 Apr 2025

    NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-9413

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Internet Radio Settings via the urlRedirectCustomUrl parameter to networkSettings.view. NOTE: These vulnerabilities can be exploited to conduct server-side request forgery (SSRF) attacks.

    Published: 25 Jul 2017
    6.1
    Medium

    CVE-2017-11617

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in atmail prior to version 7.8.0.2 allows remote attackers to inject arbitrary web script or HTML within the body of an email via an IMG element with both single quotes and double quotes.

    Published: 25 Jul 2017
    9.8
    Critical

    CVE-2017-11614

    Last Modified: 20 Apr 2025

    MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient and financial information. Connex utilizes an IBM i DB2 user account for database access. The account name is HMSCXPDN. Its password is hard-coded in multiple places in the application. Customers do not have the option to change this password. The account has elevated DB2 roles, and can access all objects or database tables on the customer DB2 database. This account can access data through ODBC, FTP, and TELNET. Customers without Connex installed are still vulnerable because the MEDHOST setup program creates this account.

    Published: 25 Jul 2017
    7.8
    High

    CVE-2017-11566

    Last Modified: 20 Apr 2025

    AppUse 4.0 allows shell command injection via a proxy field.

    Published: 25 Jul 2017
    9.8
    Critical

    CVE-2015-8009

    Last Modified: 20 Apr 2025

    The MWOAuthDataStore::lookup_token function in Extension:OAuth for MediaWiki 1.25.x before 1.25.3, 1.24.x before 1.24.4, and before 1.23.11 does not properly validate the signature when checking the authorization signature, which allows remote registered Consumers to use another Consumer's credentials by leveraging knowledge of the credentials.

    Published: 25 Jul 2017
    6.7
    Medium

    CVE-2017-9457

    Last Modified: 20 Apr 2025

    Intense PC Phoenix SecureCore UEFI firmware does not perform capsule signature validation before upgrading the system firmware. The absence of signature validation allows an attacker with administrator privileges to flash a modified UEFI BIOS.

    Published: 25 Jul 2017
    7.5
    High

    CVE-2017-8035

    Last Modified: 20 Apr 2025

    An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for that installation.

    Published: 25 Jul 2017
    7.8
    High

    CVE-2017-8033

    Last Modified: 20 Apr 2025

    An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted application that can write arbitrary files to the Cloud Controller VM.

    Published: 25 Jul 2017
    8.8
    High

    CVE-2017-7000

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 25 Jul 2017