CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-3081

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability during internal computation caused by multiple display object mask manipulations. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-3082

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the LocaleID class. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-9620

    Last Modified: 20 Apr 2025

    The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document, related to the xps_encode_font_char_imp function.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-9726

    Last Modified: 20 Apr 2025

    The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 13 Jun 2017
    7.8
    High

    CVE-2017-9727

    Last Modified: 20 Apr 2025

    The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-3078

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-3083

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the Primetime SDK functionality related to the profile metadata of the media stream. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Jun 2017
    9.8
    Critical

    CVE-2017-3084

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable use after free vulnerability in the advertising metadata functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 13 Jun 2017
    7.5
    High

    CVE-2017-9604

    Last Modified: 20 Apr 2025

    KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 13 Jun 2017
    5.4
    Medium

    CVE-2017-1247

    Last Modified: 20 Apr 2025

    IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124627.

    Published: 12 Jun 2017
    5.4
    Medium

    CVE-2017-1276

    Last Modified: 20 Apr 2025

    IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124751.

    Published: 12 Jun 2017
    5.7
    Medium

    CVE-2017-1214

    Last Modified: 20 Apr 2025

    IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. IBM X-Force ID: 123854.

    Published: 12 Jun 2017
    5.4
    Medium

    CVE-2017-1278

    Last Modified: 20 Apr 2025

    IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0 and 6.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 124756.

    Published: 12 Jun 2017
    6.1
    Medium

    CVE-2017-7665

    Last Modified: 20 Apr 2025

    In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.

    Published: 12 Jun 2017
    7.5
    High

    CVE-2017-7667

    Last Modified: 20 Apr 2025

    Apache NiFi before 0.7.4 and 1.x before 1.3.0 need to establish the response header telling browsers to only allow framing with the same origin.

    Published: 12 Jun 2017
    7.5
    High

    CVE-2017-9557

    Last Modified: 20 Apr 2025

    register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.

    Published: 12 Jun 2017
    8.8
    High

    CVE-2017-9418

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.

    Published: 12 Jun 2017
    8.8
    High

    CVE-2017-9324

    Last Modified: 20 Apr 2025

    In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end.

    Published: 12 Jun 2017
    5.4
    Medium

    CVE-2017-9547

    Last Modified: 20 Apr 2025

    admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change).

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9123

    Last Modified: 20 Apr 2025

    The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9124

    Last Modified: 20 Apr 2025

    The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9125

    Last Modified: 20 Apr 2025

    The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9126

    Last Modified: 20 Apr 2025

    The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9127

    Last Modified: 20 Apr 2025

    The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9128

    Last Modified: 20 Apr 2025

    The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.

    Published: 12 Jun 2017
    5.7
    Medium

    CVE-2017-9546

    Last Modified: 20 Apr 2025

    admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name.

    Published: 12 Jun 2017
    7.5
    High

    CVE-2017-9543

    Last Modified: 20 Apr 2025

    register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm.

    Published: 12 Jun 2017
    9.8
    Critical

    CVE-2017-9544

    Last Modified: 20 Apr 2025

    There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.

    Published: 12 Jun 2017
    6.5
    Medium

    CVE-2017-9122

    Last Modified: 20 Apr 2025

    The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.

    Published: 12 Jun 2017
    5.4
    Medium

    CVE-2017-9548

    Last Modified: 20 Apr 2025

    admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page that is scheduled for future publication (aka a pending page change).

    Published: 12 Jun 2017
    9.8
    Critical

    CVE-2014-9984

    Last Modified: 20 Apr 2025

    nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd.

    Published: 12 Jun 2017
    6.1
    Medium

    CVE-2015-9096

    Last Modified: 20 Apr 2025

    Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a RCPT TO or MAIL FROM command, as demonstrated by CRLF sequences immediately before and after a DATA substring.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9780

    Last Modified: 20 Apr 2025

    In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the "system helper" component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9610

    Last Modified: 20 Apr 2025

    The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9611

    Last Modified: 20 Apr 2025

    The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9612

    Last Modified: 20 Apr 2025

    The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9618

    Last Modified: 20 Apr 2025

    The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted document.

    Published: 12 Jun 2017
    7.8
    High

    CVE-2017-9619

    Last Modified: 20 Apr 2025

    The xps_true_callback_glyph_name function in xps/xpsttf.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (Segmentation Violation and application crash) via a crafted file.

    Published: 12 Jun 2017
    5.5
    Medium

    CVE-2017-1000380

    Last Modified: 20 Apr 2025

    sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i.e., uninitialized memory contents may be disclosed when a read and an ioctl happen at the same time.

    Published: 12 Jun 2017
    9.8
    Critical

    CVE-2017-9542

    Last Modified: 20 Apr 2025

    D-Link DIR-615 Wireless N 300 Router allows authentication bypass via a modified POST request to login.cgi. This issue occurs because it fails to validate the password field. Successful exploitation of this issue allows an attacker to take control of the affected device.

    Published: 11 Jun 2017
    7.8
    High

    CVE-2017-9527

    Last Modified: 20 Apr 2025

    The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.

    Published: 11 Jun 2017
    7.5
    High

    CVE-2017-9763

    Last Modified: 20 Apr 2025

    The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array.

    Published: 11 Jun 2017
    7.8
    High

    CVE-2017-10140

    Last Modified: 21 Nov 2024

    Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the current directory.

    Published: 11 Jun 2017
    7.5
    High

    CVE-2017-10664

    Last Modified: 20 Apr 2025

    qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

    Published: 11 Jun 2017
    5.4
    Medium

    CVE-2017-5004

    Last Modified: 20 Apr 2025

    EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Stored Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an affected system.

    Published: 9 Jun 2017
    6.1
    Medium

    CVE-2017-5003

    Last Modified: 20 Apr 2025

    EMC RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2 (all patch levels); RSA Via Lifecycle and Governance version 7.0 (all patch levels); and RSA Identity Management and Governance (IMG) version 6.9.1 (all patch levels) have Reflected Cross Site Scripting vulnerabilities that could potentially be exploited by malicious users to compromise an affected system.

    Published: 9 Jun 2017
    7.5
    High

    CVE-2017-0375

    Last Modified: 20 Apr 2025

    The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.

    Published: 9 Jun 2017
    7.5
    High

    CVE-2017-0376

    Last Modified: 20 Apr 2025

    The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.

    Published: 9 Jun 2017
    9.8
    Critical

    CVE-2016-7836

    Last Modified: 22 Apr 2026

    SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.

    Published: 9 Jun 2017
    7.8
    High

    CVE-2016-7838

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in WinSparkle versions prior to 0.5.3 allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.

    Published: 9 Jun 2017