CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-4985

    Last Modified: 20 Apr 2025

    In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user may potentially escalate their privileges to root due to authorization checks not being performed on certain perl scripts. This may potentially be exploited by an attacker to run arbitrary commands as root on the targeted VNX Control Station system.

    Published: 19 Jun 2017
    7.3
    High

    CVE-2017-4987

    Last Modified: 20 Apr 2025

    In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-4984

    Last Modified: 20 Apr 2025

    In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-9730

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9744

    Last Modified: 20 Apr 2025

    The sh_elf_set_mach_from_flags function in bfd/elf32-sh.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9749

    Last Modified: 20 Apr 2025

    The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9746

    Last Modified: 20 Apr 2025

    The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of rae insns printing for this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9750

    Last Modified: 20 Apr 2025

    opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9755

    Last Modified: 20 Apr 2025

    opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of registers for bnd mode, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9756

    Last Modified: 20 Apr 2025

    The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9745

    Last Modified: 20 Apr 2025

    The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9747

    Last Modified: 20 Apr 2025

    The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9748

    Last Modified: 20 Apr 2025

    The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9751

    Last Modified: 20 Apr 2025

    opcodes/rl78-decode.opc in GNU Binutils 2.28 has an unbounded GETBYTE macro, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9752

    Last Modified: 20 Apr 2025

    bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file in the _bfd_vms_get_value and _bfd_vms_slurp_etir functions during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9753

    Last Modified: 20 Apr 2025

    The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9754

    Last Modified: 20 Apr 2025

    The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    6.1
    Medium

    CVE-2018-5712

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-1000366

    Last Modified: 20 Apr 2025

    glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-1000379

    Last Modified: 20 Apr 2025

    The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.

    Published: 19 Jun 2017
    6.5
    Medium

    CVE-2017-10972

    Last Modified: 29 Aug 2025

    Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

    Published: 19 Jun 2017
    8.8
    High

    CVE-2017-10971

    Last Modified: 29 Aug 2025

    In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-9742

    Last Modified: 20 Apr 2025

    The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 19 Jun 2017
    7.5
    High

    CVE-2017-9766

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.

    Published: 19 Jun 2017
    7.4
    High

    CVE-2017-1000364

    Last Modified: 20 Apr 2025

    An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-1000365

    Last Modified: 20 Apr 2025

    The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this limitation. This affects Linux Kernel versions 4.11.5 and earlier. It appears that this feature was introduced in the Linux Kernel version 2.6.23.

    Published: 19 Jun 2017
    4
    Medium

    CVE-2017-1000369

    Last Modified: 20 Apr 2025

    Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that at this time upstream has released a patch (commit 65e061b76867a9ea7aeeb535341b790b90ae6c21), but it is not known if a new point release is available that addresses this issue at this time.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-1000370

    Last Modified: 20 Apr 2025

    The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.

    Published: 19 Jun 2017
    7.8
    High

    CVE-2017-1000371

    Last Modified: 20 Apr 2025

    The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.

    Published: 19 Jun 2017
    9.8
    Critical

    CVE-2017-9741

    Last Modified: 20 Apr 2025

    install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TABLES_PREFIX in the configuration file.

    Published: 18 Jun 2017
    6.1
    Medium

    CVE-2017-9668

    Last Modified: 20 Apr 2025

    In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.

    Published: 18 Jun 2017
    7.8
    High

    CVE-2017-9743

    Last Modified: 20 Apr 2025

    The print_insn_score32 function in opcodes/score7-dis.c:552 in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.

    Published: 18 Jun 2017
    9.8
    Critical

    CVE-2017-9736

    Last Modified: 20 Apr 2025

    SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.

    Published: 17 Jun 2017
    7.5
    High

    CVE-2017-9231

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via unspecified vectors.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2016-1000221

    Last Modified: 20 Apr 2025

    Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.

    Published: 16 Jun 2017
    6.1
    Medium

    CVE-2015-9056

    Last Modified: 20 Apr 2025

    Kibana versions prior to 4.1.3 and 4.2.1 are vulnerable to a XSS attack.

    Published: 16 Jun 2017
    8.8
    High

    CVE-2016-1000218

    Last Modified: 20 Apr 2025

    Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate superfluous reports whenever an authenticated Kibana user navigates to a specially-crafted page.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2016-1000222

    Last Modified: 20 Apr 2025

    Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas in the CSV data.

    Published: 16 Jun 2017
    6.1
    Medium

    CVE-2016-10366

    Last Modified: 20 Apr 2025

    Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.

    Published: 16 Jun 2017
    6.5
    Medium

    CVE-2016-10362

    Last Modified: 20 Apr 2025

    Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2016-10363

    Last Modified: 20 Apr 2025

    Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

    Published: 16 Jun 2017
    6.5
    Medium

    CVE-2016-10364

    Last Modified: 20 Apr 2025

    With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any authenticated user could make requests to those services regardless of their own permissions.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2017-8452

    Last Modified: 20 Apr 2025

    Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certain requests and will accumulate over time until the process crashes.

    Published: 16 Jun 2017
    5.9
    Medium

    CVE-2017-8449

    Last Modified: 20 Apr 2025

    X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and exclude rules when merging multiple rules with field level security rules for the same index.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2017-8450

    Last Modified: 20 Apr 2025

    X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.

    Published: 16 Jun 2017
    6.2
    Medium

    CVE-2017-6899

    Last Modified: 20 Apr 2025

    The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm8916 through 2017-06-16 in LineageOS, and possibly other kernels for MSM devices, allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted /sys/kernel/debug/msm-bus-dbg/client-data/update-request write request.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2017-9729

    Last Modified: 20 Apr 2025

    In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular expression.

    Published: 16 Jun 2017
    9.8
    Critical

    CVE-2017-9728

    Last Modified: 20 Apr 2025

    In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression.

    Published: 16 Jun 2017
    7.5
    High

    CVE-2017-9731

    Last Modified: 20 Apr 2025

    In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive information by reading a URL in a Source entry in an ipk package.

    Published: 16 Jun 2017
    9.8
    Critical

    CVE-2017-9602

    Last Modified: 20 Apr 2025

    KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

    Published: 16 Jun 2017