CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-0682

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36588422.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0683

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36591008.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0666

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37285689.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0670

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36104177.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0672

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android libraries. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-34778578.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0673

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33974623.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0684

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0685

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34203195.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0686

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231231.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0688

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35584425.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0689

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36215950.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0693

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36993291.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0694

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37093318.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0695

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37094889.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0696

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37207120.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0699

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490809.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0700

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0701

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36385715.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0703

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0704

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-33059280.

    Published: 6 Jul 2017
    6.8
    Medium

    CVE-2017-0705

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-34973477. References: B-RB#119898.

    Published: 6 Jul 2017
    6.8
    Medium

    CVE-2017-0706

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Broadcom wi-fi driver. Product: Android. Versions: Android kernel. Android ID: A-35195787. References: B-RB#120532.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0664

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Android framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36491278.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0674

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34231163.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0675

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0676

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34896431.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0677

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36035074.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0678

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0680

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37008096.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0691

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0707

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the HTC led driver. Product: Android. Versions: Android kernel. Android ID: A-36088467.

    Published: 6 Jul 2017
    5.5
    Medium

    CVE-2017-0708

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.

    Published: 6 Jul 2017
    3.3
    Low

    CVE-2017-0709

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-0710

    Last Modified: 20 Apr 2025

    A elevation of privilege vulnerability in the Upstream Linux tcb. Product: Android. Versions: Android kernel. Android ID: A-34951864.

    Published: 6 Jul 2017
    7.8
    High

    CVE-2017-6247

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of local arbitrary code execution in a privileged process in the kernel. Product: Android. Versions: N/A. Android ID: A-34386301. References: N-CVE-2017-6247.

    Published: 6 Jul 2017
    7
    High

    CVE-2017-6248

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34372667. References: N-CVE-2017-6248.

    Published: 6 Jul 2017
    6.5
    Medium

    CVE-2017-10973

    Last Modified: 20 Apr 2025

    In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.

    Published: 6 Jul 2017
    6.1
    Medium

    CVE-2017-10967

    Last Modified: 20 Apr 2025

    In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.

    Published: 6 Jul 2017
    7.5
    High

    CVE-2017-8290

    Last Modified: 20 Apr 2025

    A potential Buffer Overflow Vulnerability (from a BB Code handling issue) has been identified in TeamSpeak Server version 3.0.13.6 (08/11/2016 09:48:33), it enables the users to Crash any WINDOWS Client that clicked into a Vulnerable Channel of a TeamSpeak Server.

    Published: 6 Jul 2017
    7.5
    High

    CVE-2017-10976

    Last Modified: 20 Apr 2025

    When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.

    Published: 6 Jul 2017
    6.5
    Medium

    CVE-2017-1236

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 9.0.2 could allow an authenticated user to potentially cause a denial of service by saving an incorrect channel status inquiry. IBM X-Force ID: 124354

    Published: 6 Jul 2017
    6.1
    Medium

    CVE-2017-10975

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Lutim before 0.8 might allow remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in an upload notification and in the myfiles component, if the attacker can convince the victim to proceed with an upload despite the appearance of an XSS payload in the filename.

    Published: 6 Jul 2017
    5.4
    Medium

    CVE-2017-10970

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-10989

    Last Modified: 20 Apr 2025

    The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer over-read or possibly unspecified other impact.

    Published: 6 Jul 2017
    6.1
    Medium

    CVE-2017-11507

    Last Modified: 20 Apr 2025

    A cross site scripting (XSS) vulnerability exists in Check_MK versions 1.2.8x prior to 1.2.8p25 and 1.4.0x prior to 1.4.0p9, allowing an unauthenticated attacker to inject arbitrary HTML or JavaScript via the output_format parameter, and the username parameter of failed HTTP basic authentication attempts, which is returned unencoded in an internal server error page.

    Published: 6 Jul 2017
    9.1
    Critical

    CVE-2017-6711

    Last Modified: 20 Apr 2025

    A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulnerability is due to an insecure default configuration of the Apache ZooKeeper service used by the affected software. An attacker could exploit this vulnerability by accessing the affected device through the orchestrator network. An exploit could allow the attacker to gain access to ZooKeeper data nodes (znodes) and influence the behavior of the system's high-availability feature. This vulnerability affects all releases of Cisco Ultra Services Framework UAS prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvd29395.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-6708

    Last Modified: 20 Apr 2025

    A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to read sensitive files or execute malicious code on an affected system. The vulnerability is due to the absence of validation checks for the input that is used to create symbolic links. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76654.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-6709

    Last Modified: 20 Apr 2025

    A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected system. The vulnerability exists because the affected software logs administrative credentials in clear text for Cisco ESC and Cisco OpenStack deployment purposes. An attacker could exploit this vulnerability by accessing the AutoVNF URL for the location where the log files are stored and subsequently accessing the administrative credentials that are stored in clear text in those log files. This vulnerability affects all releases of the Cisco Ultra Services Framework prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76659.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-6713

    Last Modified: 20 Apr 2025

    A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default credentials for the Cisco ESC UI that are shared between installations. An attacker who can extract the static credentials from an existing installation of Cisco ESC could generate an admin session token that allows access to all instances of the ESC web UI. This vulnerability affects Cisco Elastic Services Controller prior to releases 2.3.1.434 and 2.3.2. Cisco Bug IDs: CSCvc76627.

    Published: 6 Jul 2017
    9.8
    Critical

    CVE-2017-6714

    Last Modified: 20 Apr 2025

    A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An attacker could exploit this vulnerability by crafting CLI command inputs to execute Linux shell commands as the root user. This vulnerability affects all releases of Cisco Ultra Services Framework Staging Server prior to Releases 5.0.3 and 5.1. Cisco Bug IDs: CSCvc76673.

    Published: 6 Jul 2017