CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2017-8005

    Last Modified: 20 Apr 2025

    The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identity Management and Governance (RSA IMG) versions 6.9.1, all patch levels) are affected by multiple stored cross-site scripting vulnerabilities. Remote authenticated malicious users could potentially inject arbitrary HTML code to the application.

    Published: 17 Jul 2017
    5.9
    Medium

    CVE-2017-8006

    Last Modified: 20 Apr 2025

    In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of RSA Authentication Manager as a target user can use a brute force attack to attempt to identify that user's PIN. The malicious user could potentially reset the compromised PIN to affect victim's ability to obtain access to protected resources.

    Published: 17 Jul 2017
    6.6
    Medium

    CVE-2017-8034

    Last Modified: 20 Apr 2025

    The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-11367

    Last Modified: 20 Apr 2025

    The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and application crash) via malformed compressed data.

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-11354

    Last Modified: 20 Apr 2025

    Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.

    Published: 17 Jul 2017
    5.9
    Medium

    CVE-2017-11353

    Last Modified: 20 Apr 2025

    yadm (yet another dotfile manager) 1.10.0 has a race condition (related to the behavior of git commands in setting permissions for new files and directories), which potentially allows access to SSH and PGP keys.

    Published: 17 Jul 2017
    6.5
    Medium

    CVE-2017-11360

    Last Modified: 20 Apr 2025

    The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge number_pixels value.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10983

    Last Modified: 20 Apr 2025

    An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of service.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10981

    Last Modified: 20 Apr 2025

    An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.

    Published: 17 Jul 2017
    6.5
    Medium

    CVE-2017-11352

    Last Modified: 20 Apr 2025

    In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-1000199

    Last Modified: 20 Apr 2025

    tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-9951

    Last Modified: 20 Apr 2025

    The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of service (segmentation fault) via a request to add/set a key, which makes a comparison between signed and unsigned int and triggers a heap-based buffer over-read. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8705.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10978

    Last Modified: 20 Apr 2025

    An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-10979

    Last Modified: 20 Apr 2025

    An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10980

    Last Modified: 20 Apr 2025

    An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.

    Published: 17 Jul 2017
    3.7
    Low

    CVE-2017-10988

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-10984

    Last Modified: 20 Apr 2025

    An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10986

    Last Modified: 20 Apr 2025

    An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10987

    Last Modified: 20 Apr 2025

    An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.

    Published: 17 Jul 2017
    5.7
    Medium

    CVE-2017-11348

    Last Modified: 20 Apr 2025

    In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a maliciously crafted NuGet package, potentially overwriting other packages or modifying system files. This is a directory traversal in the PackageId value.

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-11362

    Last Modified: 20 Apr 2025

    In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact within International Components for Unicode (ICU) for C/C++ via a long first argument to the msgfmt_parse_message function.

    Published: 17 Jul 2017
    7.8
    High

    CVE-2017-11421

    Last Modified: 20 Apr 2025

    gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename.

    Published: 17 Jul 2017
    5.5
    Medium

    CVE-2017-11434

    Last Modified: 20 Apr 2025

    The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-11553

    Last Modified: 20 Apr 2025

    There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.

    Published: 17 Jul 2017
    8.8
    High

    CVE-2017-12668

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePCXImage in coders/pcx.c.

    Published: 17 Jul 2017
    8.8
    High

    CVE-2017-12669

    Last Modified: 20 Apr 2025

    ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteCALSImage in coders/cals.c.

    Published: 17 Jul 2017
    7.8
    High

    CVE-2017-7541

    Last Modified: 20 Apr 2025

    The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted NL80211_CMD_FRAME Netlink packet.

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-11349

    Last Modified: 30 Apr 2026

    dataTaker DT8x dEX 1.72.007 allows remote attackers to compose programs or schedules, for purposes such as sending e-mail messages or making outbound connections to FTP servers for uploading data.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10985

    Last Modified: 20 Apr 2025

    An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

    Published: 17 Jul 2017
    7.5
    High

    CVE-2017-10982

    Last Modified: 20 Apr 2025

    An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.

    Published: 17 Jul 2017
    9.8
    Critical

    CVE-2017-11346

    Last Modified: 20 Apr 2025

    Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk videos.

    Published: 16 Jul 2017
    8.8
    High

    CVE-2017-11347

    Last Modified: 20 Apr 2025

    Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.

    Published: 16 Jul 2017
    7.8
    High

    CVE-2017-11344

    Last Modified: 20 Apr 2025

    Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to write shellcode at any address in the heap; this can be used to execute arbitrary code on the router by hosting a crafted device description XML document at a URL specified within a Location header in an SSDP response.

    Published: 16 Jul 2017
    7.8
    High

    CVE-2017-11345

    Last Modified: 20 Apr 2025

    Stack buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-N56U, RT-AC3200, RT-AC3100, RT_AC1200GU, RT_AC1200G, RT-AC1200, RT-AC53, RT-N12HP, RT-N12HP_B1, RT-N12D1, RT-N12+, RT_N12+_PRO, RT-N16, and RT-N300 devices allows remote attackers to execute arbitrary code on the router by hosting a crafted device description XML document (that includes a serviceType element) at a URL specified within a Location header in an SSDP response.

    Published: 16 Jul 2017
    7.5
    High

    CVE-2017-11343

    Last Modified: 20 Apr 2025

    Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, will result in O(n) lookup time.

    Published: 16 Jul 2017
    7.5
    High

    CVE-2017-11341

    Last Modified: 20 Apr 2025

    There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

    Published: 16 Jul 2017
    7.5
    High

    CVE-2017-11342

    Last Modified: 20 Apr 2025

    There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11533

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uil.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11540

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called from the WritePICONImage function in coders/xpm.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11531

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteHISTOGRAMImage() function in coders/histogram.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11532

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11534

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the lite_font_map() function in coders/wmf.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11535

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WritePSImage() function in coders/ps.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11536

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteJP2Image() function in coders/jp2.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11537

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Floating Point Exception (FPE) in the WritePALMImage() function in coders/palm.c, related to an incorrect bits-per-pixel calculation.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11538

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteOnePNGImage() function in coders/png.c.

    Published: 16 Jul 2017
    6.5
    Medium

    CVE-2017-11539

    Last Modified: 20 Apr 2025

    When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadOnePNGImage() function in coders/png.c.

    Published: 16 Jul 2017
    7.2
    High

    CVE-2015-0249

    Last Modified: 20 Apr 2025

    The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).

    Published: 14 Jul 2017
    9.1
    Critical

    CVE-2016-6793

    Last Modified: 20 Apr 2025

    The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.

    Published: 14 Jul 2017
    9.8
    Critical

    CVE-2017-0028

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user, aka "Scripting Engine Memory Corruption Vulnerability."

    Published: 14 Jul 2017