CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-4907

    Last Modified: 20 Apr 2025

    VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4908

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4913

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulnerability in the True Type Font parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-6638

    Last Modified: 20 Apr 2025

    A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYSTEM account. The vulnerability is due to incomplete input validation of path and file names of a DLL file before it is loaded. An attacker could exploit this vulnerability by creating a malicious DLL file and installing it in a specific system directory. A successful exploit could allow the attacker to execute commands on the underlying Microsoft Windows host with privileges equivalent to the SYSTEM account. The attacker would need valid user credentials to exploit this vulnerability. This vulnerability affects all Cisco AnyConnect Secure Mobility Client for Windows software versions prior to 4.4.02034. Cisco Bug IDs: CSCvc97928.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2017-6639

    Last Modified: 20 Apr 2025

    A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root privileges on an affected system. The vulnerability is due to the lack of authentication and authorization mechanisms for a debugging tool that was inadvertently enabled in the affected software. An attacker could exploit this vulnerability by remotely connecting to the debugging tool via TCP. A successful exploit could allow the attacker to access sensitive information about the affected software or execute arbitrary code with root privileges on the affected system. This vulnerability affects Cisco Prime Data Center Network Manager (DCNM) Software Releases 10.1(1) and 10.1(2) for Microsoft Windows, Linux, and Virtual Appliance platforms. Cisco Bug IDs: CSCvd09961.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2017-6648

    Last Modified: 20 Apr 2025

    A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint (CE) Software could allow an unauthenticated, remote attacker to cause a TelePresence endpoint to reload unexpectedly, resulting in a denial of service (DoS) condition. The vulnerability is due to a lack of flow-control mechanisms within the software. An attacker could exploit this vulnerability by sending a flood of SIP INVITE packets to the affected device. An exploit could allow the attacker to impact the availability of services and data of the device, including a complete DoS condition. This vulnerability affects the following Cisco TC and CE platforms when running software versions prior to TC 7.3.8 and CE 8.3.0. Cisco Bug IDs: CSCux94002.

    Published: 8 Jun 2017
    5.4
    Medium

    CVE-2017-9516

    Last Modified: 20 Apr 2025

    Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4911

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    7.8
    High

    CVE-2017-4912

    Last Modified: 20 Apr 2025

    VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.

    Published: 8 Jun 2017
    7.3
    High

    CVE-2017-7180

    Last Modified: 20 Apr 2025

    Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.

    Published: 8 Jun 2017
    7.5
    High

    CVE-2018-9259

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.

    Published: 8 Jun 2017
    7.1
    High

    CVE-2017-13305

    Last Modified: 21 Nov 2024

    A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.

    Published: 8 Jun 2017
    5.5
    Medium

    CVE-2017-15274

    Last Modified: 20 Apr 2025

    security/keys/keyctl.c in the Linux kernel before 4.11.5 does not consider the case of a NULL payload in conjunction with a nonzero length value, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted add_key or keyctl system call, a different vulnerability than CVE-2017-12192.

    Published: 8 Jun 2017
    9.8
    Critical

    CVE-2017-10788

    Last Modified: 20 Apr 2025

    The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

    Published: 8 Jun 2017
    5.5
    Medium

    CVE-2017-9616

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box function in epan/dissectors/file-mp4.c.

    Published: 8 Jun 2017
    6.1
    Medium

    CVE-2014-9310

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2015-7346

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in ZCMS 1.1.

    Published: 7 Jun 2017
    5.3
    Medium

    CVE-2015-3295

    Last Modified: 20 Apr 2025

    markdown-it before 4.1.0 does not block data: URLs.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2015-8235

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Spiffy before 5.4.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2015-5175

    Last Modified: 20 Apr 2025

    Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

    Published: 7 Jun 2017
    Unknown

    CVE-2015-5202

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-5233. Reason: This candidate is a reservation duplicate of CVE-2015-5233. Notes: All CVE users should reference CVE-2015-5233 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Jun 2017
    6.1
    Medium

    CVE-2015-6540

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.

    Published: 7 Jun 2017
    5.4
    Medium

    CVE-2015-6959

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Vindula 1.9.

    Published: 7 Jun 2017
    7.3
    High

    CVE-2017-7965

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMachine HVAC v2.1.0 for Modicon M171/M172 Controller.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2017-7966

    Last Modified: 20 Apr 2025

    A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.

    Published: 7 Jun 2017
    7.4
    High

    CVE-2017-9355

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2017-4902

    Last Modified: 20 Apr 2025

    VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2017-4898

    Last Modified: 20 Apr 2025

    VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx" process loading DLLs from a path defined in the local environment-variable. Successful exploitation of this issue may allow normal users to escalate privileges to System in the host machine where VMware Workstation is installed.

    Published: 7 Jun 2017
    4.7
    Medium

    CVE-2017-4899

    Last Modified: 20 Apr 2025

    VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An attacker may exploit this issue to crash the VM or trigger an out-of-bound read. Note: This issue can be triggered only when the host has no graphics card or no graphics drivers are installed.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-4900

    Last Modified: 20 Apr 2025

    VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SVGA driver. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2017-4904

    Last Modified: 20 Apr 2025

    The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 has uninitialized memory usage. This issue may allow a guest to execute code on the host. The issue is reduced to a Denial of Service of the guest on ESXi 5.5.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-4905

    Last Modified: 20 Apr 2025

    VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have uninitialized memory usage. This issue may lead to an information leak.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2017-4903

    Last Modified: 20 Apr 2025

    VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi600-201703403-SG, 6.0 U1 without patch ESXi600-201703402-SG, and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have an uninitialized stack memory usage in SVGA. This issue may allow a guest to execute code on the host.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2016-6087

    Last Modified: 20 Apr 2025

    IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange validation. IBM X-Force ID: 117918.

    Published: 7 Jun 2017
    8.8
    High

    CVE-2016-9977

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2016-8939

    Last Modified: 20 Apr 2025

    IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can be compromised. IBM X-Force ID: 118790.

    Published: 7 Jun 2017
    5.3
    Medium

    CVE-2016-5959

    Last Modified: 20 Apr 2025

    IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 116136.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2017-4917

    Last Modified: 20 Apr 2025

    VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained.

    Published: 7 Jun 2017
    6.5
    Medium

    CVE-2016-0254

    Last Modified: 20 Apr 2025

    IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote authenticated attacker could exploit this vulnerability to consume all available CPU resources and cause a denial of service. IBM X-Force ID: 110563.

    Published: 7 Jun 2017
    6.5
    Medium

    CVE-2016-3019

    Last Modified: 20 Apr 2025

    IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.

    Published: 7 Jun 2017
    4.3
    Medium

    CVE-2016-3051

    Last Modified: 20 Apr 2025

    IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2016-5960

    Last Modified: 20 Apr 2025

    IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2016-6089

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.

    Published: 7 Jun 2017
    3.3
    Low

    CVE-2017-1125

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.

    Published: 7 Jun 2017
    6.1
    Medium

    CVE-2017-1178

    Last Modified: 20 Apr 2025

    IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123430.

    Published: 7 Jun 2017
    5.4
    Medium

    CVE-2017-1305

    Last Modified: 20 Apr 2025

    IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125459.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2017-4914

    Last Modified: 20 Apr 2025

    VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of this issue may allow a remote attacker to execute commands on the appliance.

    Published: 7 Jun 2017
    5.3
    Medium

    CVE-2016-9710

    Last Modified: 20 Apr 2025

    IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2017-1196

    Last Modified: 20 Apr 2025

    IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-7564

    Last Modified: 8 Jun 2026

    In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers.

    Published: 7 Jun 2017