CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-9775

    Last Modified: 20 Apr 2025

    Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

    Published: 21 Jun 2017
    10
    Critical

    CVE-2017-3088

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF runtime engine. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3090

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of browser related library extensions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3086

    Last Modified: 20 Apr 2025

    Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-3087

    Last Modified: 20 Apr 2025

    Adobe Captivate versions 9 and earlier have an information disclosure vulnerability resulting from abuse of the quiz reporting feature in Captivate.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3089

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF imaging model. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3092

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading of editor control library functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3093

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the bitmap representation module. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3094

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF processing engine. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3095

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the PDF parsing engine. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3097

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier contain an insecure library loading vulnerability. The vulnerability is due to unsafe library loading functions in the installer plugin. A successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3098

    Last Modified: 20 Apr 2025

    Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and write arbitrary files to the server.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3096

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.4 and earlier have an exploitable memory corruption vulnerability in the character code mapping module. Successful exploitation could lead to arbitrary code execution.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-7668

    Last Modified: 20 Apr 2025

    The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force ap_find_token() to return an incorrect value.

    Published: 20 Jun 2017
    6.5
    Medium

    CVE-2017-10911

    Last Modified: 20 Apr 2025

    The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

    Published: 20 Jun 2017
    8.1
    High

    CVE-2017-10914

    Last Modified: 20 Apr 2025

    The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

    Published: 20 Jun 2017
    9.1
    Critical

    CVE-2017-10917

    Last Modified: 20 Apr 2025

    Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

    Published: 20 Jun 2017
    10
    Critical

    CVE-2017-10920

    Last Modified: 20 Apr 2025

    The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.

    Published: 20 Jun 2017
    6.5
    Medium

    CVE-2017-10923

    Last Modified: 20 Apr 2025

    Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3169

    Last Modified: 20 Apr 2025

    In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3216

    Last Modified: 20 Apr 2025

    WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypass allowing a remote, unauthenticated attacker to gain administrator access to the device by performing an administrator password change on the device via a crafted POST request.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-3743

    Last Modified: 20 Apr 2025

    If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text password that were used to access the second machine during the time the command is processing.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-7679

    Last Modified: 20 Apr 2025

    In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-1000381

    Last Modified: 20 Apr 2025

    The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given input buffer if the passed in DNS response packet was crafted in a particular way.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-10913

    Last Modified: 20 Apr 2025

    The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

    Published: 20 Jun 2017
    9
    Critical

    CVE-2017-10915

    Last Modified: 20 Apr 2025

    The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

    Published: 20 Jun 2017
    10
    Critical

    CVE-2017-10918

    Last Modified: 20 Apr 2025

    Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

    Published: 20 Jun 2017
    6.5
    Medium

    CVE-2017-10919

    Last Modified: 20 Apr 2025

    Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

    Published: 20 Jun 2017
    10
    Critical

    CVE-2017-10921

    Last Modified: 20 Apr 2025

    The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-10922

    Last Modified: 20 Apr 2025

    The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-3214

    Last Modified: 20 Apr 2025

    The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.

    Published: 20 Jun 2017
    5.3
    Medium

    CVE-2017-3215

    Last Modified: 20 Apr 2025

    The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, in combination with a user_id can be used to perform user actions.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-7659

    Last Modified: 20 Apr 2025

    A maliciously constructed HTTP/2 request could cause mod_http2 in Apache HTTP Server 2.4.24, 2.4.25 to dereference a NULL pointer and crash the server process.

    Published: 20 Jun 2017
    7.8
    High

    CVE-2017-9984

    Last Modified: 20 Apr 2025

    The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecified other impact by changing the value of a message queue head pointer between two kernel reads of that value, aka a "double fetch" vulnerability.

    Published: 20 Jun 2017
    9.8
    Critical

    CVE-2017-3167

    Last Modified: 4 Nov 2025

    In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.

    Published: 20 Jun 2017
    10
    Critical

    CVE-2017-10912

    Last Modified: 20 Apr 2025

    Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

    Published: 20 Jun 2017
    7.5
    High

    CVE-2017-10916

    Last Modified: 20 Apr 2025

    The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

    Published: 20 Jun 2017
    6.5
    Medium

    CVE-2017-3744

    Last Modified: 20 Apr 2025

    In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.

    Published: 20 Jun 2017
    7.8
    High

    CVE-2017-3745

    Last Modified: 20 Apr 2025

    In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password information for users that have previously authenticated to the LXCA's internal LDAP server, including administrative accounts and service accounts with administrative privileges. This is an issue only for users who have used local authentication with LXCA and not remote authentication against external LDAP or ADFS servers.

    Published: 20 Jun 2017
    5.9
    Medium

    CVE-2017-1000377

    Last Modified: 20 Apr 2025

    An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped by other Linux vendors), specifically the default stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects PAX Linux Kernel versions as of June 19, 2017 (specific version information is not available at this time).

    Published: 19 Jun 2017
    5.5
    Medium

    CVE-2017-9761

    Last Modified: 20 Apr 2025

    The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file.

    Published: 19 Jun 2017
    6.5
    Medium

    CVE-2017-1000373

    Last Modified: 20 Apr 2025

    The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-1000374

    Last Modified: 20 Apr 2025

    A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-1000375

    Last Modified: 20 Apr 2025

    NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.

    Published: 19 Jun 2017
    7
    High

    CVE-2017-1000376

    Last Modified: 20 Apr 2025

    libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vulnerable, and upstream is believed to have fixed this issue in version 3.1.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-1000372

    Last Modified: 20 Apr 2025

    A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-1000378

    Last Modified: 20 Apr 2025

    The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects NetBSD 7.1 and possibly earlier versions.

    Published: 19 Jun 2017
    5.5
    Medium

    CVE-2017-9762

    Last Modified: 20 Apr 2025

    The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file.

    Published: 19 Jun 2017
    8.8
    High

    CVE-2017-9759

    Last Modified: 20 Apr 2025

    SQL Injection exists in admin/index.php in Zenbership 1.0.8 via the filters array parameter, exploitable by a privileged account.

    Published: 19 Jun 2017
    8.8
    High

    CVE-2017-9757

    Last Modified: 20 Apr 2025

    IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated users, or through CSRF.

    Published: 19 Jun 2017