CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2017-2346

    Last Modified: 20 Apr 2025

    An MS-MPC or MS-MIC Service PIC may crash when large fragmented packets are passed through an Application Layer Gateway (ALG). Repeated crashes of the Service PC can result in an extended denial of service condition. The issue can be seen only if NAT or stateful-firewall rules are configured with ALGs enabled. This issue was caused by the code change for PR 1182910 in Junos OS 14.1X55-D30, 14.1X55-D35, 14.2R7, 15.1R5, and 16.1R2. No other versions of Junos OS and no other Juniper Networks products or platforms are affected by this issue. Affected releases are Juniper Networks Junos OS on MX platforms running: 14.1X55 from 14.1X55-D30 to releases prior to 14.1X55-D35; 14.2R from 14.2R7 to releases prior to 14.2R7-S4, 14.2R8; 15.1R from 15.1R5 to releases prior to 15.1R5-S2, 15.1R6; 16.1R from 16.1R2 to releases prior to 16.1R3-S2, 16.1R4.

    Published: 14 Jul 2017
    7.5
    High

    CVE-2017-1182

    Last Modified: 20 Apr 2025

    IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.

    Published: 14 Jul 2017
    7.5
    High

    CVE-2017-1183

    Last Modified: 20 Apr 2025

    IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.

    Published: 14 Jul 2017
    7
    High

    CVE-2017-1181

    Last Modified: 20 Apr 2025

    IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.

    Published: 14 Jul 2017
    8.1
    High

    CVE-2017-11318

    Last Modified: 20 Apr 2025

    Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abusing pre-backup events.

    Published: 14 Jul 2017
    5.5
    Medium

    CVE-2017-11328

    Last Modified: 20 Apr 2025

    Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.

    Published: 14 Jul 2017
    7.5
    High

    CVE-2017-3101

    Last Modified: 20 Apr 2025

    Adobe Connect versions 9.6.1 and earlier have a clickjacking vulnerability. Successful exploitation could lead to a clickjacking attack.

    Published: 14 Jul 2017
    6.1
    Medium

    CVE-2017-3102

    Last Modified: 20 Apr 2025

    Adobe Connect versions 9.6.1 and earlier have a reflected cross-site scripting vulnerability. Successful exploitation could lead to a reflected cross-site scripting attack.

    Published: 14 Jul 2017
    6.1
    Medium

    CVE-2017-3103

    Last Modified: 20 Apr 2025

    Adobe Connect versions 9.6.1 and earlier have a stored cross-site scripting vulnerability. Successful exploitation could lead to a stored cross-site scripting attack.

    Published: 14 Jul 2017
    7.8
    High

    CVE-2017-1000159

    Last Modified: 20 Apr 2025

    Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

    Published: 14 Jul 2017
    5.5
    Medium

    CVE-2017-1000201

    Last Modified: 20 Apr 2025

    The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

    Published: 14 Jul 2017
    8.8
    High

    CVE-2017-11335

    Last Modified: 20 Apr 2025

    There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode function in tif_zip.c). A crafted input may lead to a remote denial of service attack or an arbitrary code execution attack.

    Published: 14 Jul 2017
    6.5
    Medium

    CVE-2017-11338

    Last Modified: 20 Apr 2025

    There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.

    Published: 14 Jul 2017
    6.5
    Medium

    CVE-2017-11339

    Last Modified: 20 Apr 2025

    There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

    Published: 14 Jul 2017
    6.5
    Medium

    CVE-2017-11340

    Last Modified: 20 Apr 2025

    There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.

    Published: 14 Jul 2017
    3.5
    Low

    CVE-2017-7538

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other Satellite users.

    Published: 14 Jul 2017
    7.5
    High

    CVE-2017-1000200

    Last Modified: 20 Apr 2025

    tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service

    Published: 14 Jul 2017
    9.8
    Critical

    CVE-2017-7525

    Last Modified: 21 Nov 2024

    A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.

    Published: 14 Jul 2017
    9.8
    Critical

    CVE-2017-1000002

    Last Modified: 20 Apr 2025

    ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000011

    Last Modified: 20 Apr 2025

    MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000028

    Last Modified: 20 Apr 2025

    Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000031

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000047

    Last Modified: 20 Apr 2025

    rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000065

    Last Modified: 20 Apr 2025

    Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000073

    Last Modified: 20 Apr 2025

    Creolabs Gravity version 1.0 is vulnerable to a heap overflow in an undisclosed component that can result in arbitrary code execution.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000075

    Last Modified: 20 Apr 2025

    Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function

    Published: 13 Jul 2017
    7.8
    High

    CVE-2017-11311

    Last Modified: 20 Apr 2025

    soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.

    Published: 13 Jul 2017
    7.8
    High

    CVE-2017-1000010

    Last Modified: 20 Apr 2025

    Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.

    Published: 13 Jul 2017
    Unknown

    CVE-2017-1000055

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000009

    Last Modified: 20 Apr 2025

    Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000001

    Last Modified: 20 Apr 2025

    FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000005

    Last Modified: 20 Apr 2025

    PHPMiniAdmin version 1.9.160630 is vulnerable to stored XSS in the name of databases, tables and columns resulting in potential account takeover and scraping of data (stealing data).

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000006

    Last Modified: 20 Apr 2025

    Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000013

    Last Modified: 20 Apr 2025

    phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to an open redirect weakness

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000014

    Last Modified: 20 Apr 2025

    phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000015

    Last Modified: 20 Apr 2025

    phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a CSS injection attack through crafted cookie parameters

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000016

    Last Modified: 20 Apr 2025

    A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000017

    Last Modified: 20 Apr 2025

    phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000018

    Last Modified: 20 Apr 2025

    phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000022

    Last Modified: 20 Apr 2025

    LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.

    Published: 13 Jul 2017
    5.4
    Medium

    CVE-2017-1000023

    Last Modified: 20 Apr 2025

    LogicalDoc Community Edition 7.5.3 and prior is vulnerable to an XSS when using preview on HTML document.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000025

    Last Modified: 20 Apr 2025

    GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000027

    Last Modified: 20 Apr 2025

    Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000030

    Last Modified: 20 Apr 2025

    Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Java Key Store Password Disclosure vulnerability, that makes it possible to provide an unauthenticated attacker plain text password of administrative user and grant access to the web-based administration interface.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000032

    Last Modified: 20 Apr 2025

    Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000033

    Last Modified: 20 Apr 2025

    Wordpress Plugin Vospari Forms version < 1.4 is vulnerable to a reflected cross site scripting in the form submission resulting in javascript code execution in the context on the current user.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000035

    Last Modified: 20 Apr 2025

    Tiny Tiny RSS before 829d478f is vulnerable to XSS window.opener attack

    Published: 13 Jul 2017
    Unknown

    CVE-2017-1000036

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000039

    Last Modified: 20 Apr 2025

    Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000042

    Last Modified: 20 Apr 2025

    Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.

    Published: 13 Jul 2017