CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2017-7563

    Last Modified: 8 Jun 2026

    In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).

    Published: 7 Jun 2017
    7.5
    High

    CVE-2015-7888

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2015-7326

    Last Modified: 20 Apr 2025

    XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2015-8326

    Last Modified: 20 Apr 2025

    The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.

    Published: 7 Jun 2017
    7.8
    High

    CVE-2015-7723

    Last Modified: 20 Apr 2025

    AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.

    Published: 7 Jun 2017
    7.8
    High

    CVE-2015-7724

    Last Modified: 20 Apr 2025

    AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-7314

    Last Modified: 20 Apr 2025

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.

    Published: 7 Jun 2017
    9.8
    Critical

    CVE-2017-7312

    Last Modified: 20 Apr 2025

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-7313

    Last Modified: 20 Apr 2025

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.

    Published: 7 Jun 2017
    6.1
    Medium

    CVE-2016-9834

    Last Modified: 20 Apr 2025

    An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-9474

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-9471

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-9472

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-9473

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.

    Published: 7 Jun 2017
    5.5
    Medium

    CVE-2017-9470

    Last Modified: 20 Apr 2025

    In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

    Published: 7 Jun 2017
    6.5
    Medium

    CVE-2017-2666

    Last Modified: 21 Nov 2024

    It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

    Published: 7 Jun 2017
    7.1
    High

    CVE-2017-18926

    Last Modified: 21 Nov 2024

    raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-2670

    Last Modified: 21 Nov 2024

    It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-7507

    Last Modified: 20 Apr 2025

    GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-9468

    Last Modified: 20 Apr 2025

    In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.

    Published: 7 Jun 2017
    7.5
    High

    CVE-2017-9469

    Last Modified: 20 Apr 2025

    In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.

    Published: 7 Jun 2017
    7.7
    High

    CVE-2017-2595

    Last Modified: 21 Nov 2024

    It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.

    Published: 7 Jun 2017
    6.5
    Medium

    CVE-2017-8834

    Last Modified: 20 Apr 2025

    The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.

    Published: 7 Jun 2017
    6.5
    Medium

    CVE-2017-8871

    Last Modified: 20 Apr 2025

    The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

    Published: 7 Jun 2017
    7.1
    High

    CVE-2017-9465

    Last Modified: 20 Apr 2025

    The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

    Published: 6 Jun 2017
    6.5
    Medium

    CVE-2015-3830

    Last Modified: 20 Apr 2025

    The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.

    Published: 6 Jun 2017
    5.5
    Medium

    CVE-2016-9960

    Last Modified: 20 Apr 2025

    game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).

    Published: 6 Jun 2017
    9.8
    Critical

    CVE-2016-9961

    Last Modified: 20 Apr 2025

    game-music-emu before 0.6.1 mishandles unspecified integer values.

    Published: 6 Jun 2017
    6.5
    Medium

    CVE-2016-0767

    Last Modified: 20 Apr 2025

    PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.

    Published: 6 Jun 2017
    6.5
    Medium

    CVE-2015-1207

    Last Modified: 20 Apr 2025

    Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.

    Published: 6 Jun 2017
    7.5
    High

    CVE-2016-0768

    Last Modified: 20 Apr 2025

    PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

    Published: 6 Jun 2017
    6.5
    Medium

    CVE-2016-2192

    Last Modified: 20 Apr 2025

    PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.

    Published: 6 Jun 2017
    8.5
    High

    CVE-2017-5243

    Last Modified: 20 Apr 2025

    The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

    Published: 6 Jun 2017
    6.1
    Medium

    CVE-2017-8920

    Last Modified: 20 Apr 2025

    irc.cgi in CGI:IRC before 0.5.12 reflects user-supplied input from the R parameter without proper output encoding, aka XSS.

    Published: 6 Jun 2017
    4.8
    Medium

    CVE-2017-9452

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 6 Jun 2017
    Unknown

    CVE-2017-9422

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8920. Reason: This candidate is a reservation duplicate of CVE-2017-8920. Notes: All CVE users should reference CVE-2017-8920 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Jun 2017
    6.1
    Medium

    CVE-2017-9451

    Last Modified: 20 Apr 2025

    Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.

    Published: 6 Jun 2017
    5.4
    Medium

    CVE-2017-9448

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\modules\pages\revisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.

    Published: 6 Jun 2017
    8.8
    High

    CVE-2017-9449

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9924

    Last Modified: 20 Apr 2025

    In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9943

    Last Modified: 20 Apr 2025

    In Core Kernel in all Android releases from CAF using the Linux kernel, a Null Pointer Dereference vulnerability could potentially exist.

    Published: 6 Jun 2017
    5.5
    Medium

    CVE-2014-9951

    Last Modified: 20 Apr 2025

    In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.

    Published: 6 Jun 2017
    7
    High

    CVE-2014-9941

    Last Modified: 20 Apr 2025

    In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9949

    Last Modified: 20 Apr 2025

    In TrustZone in all Android releases from CAF using the Linux kernel, an Untrusted Pointer Dereference vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2015-9005

    Last Modified: 20 Apr 2025

    In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.

    Published: 6 Jun 2017
    7
    High

    CVE-2016-10297

    Last Modified: 20 Apr 2025

    In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9950

    Last Modified: 20 Apr 2025

    In Core Kernel in all Android releases from CAF using the Linux kernel, an Improper Authorization vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9929

    Last Modified: 20 Apr 2025

    In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9930

    Last Modified: 20 Apr 2025

    In WCDMA in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.

    Published: 6 Jun 2017
    7.8
    High

    CVE-2014-9923

    Last Modified: 20 Apr 2025

    In NAS in all Android releases from CAF using the Linux kernel, a Buffer Copy without Checking Size of Input vulnerability could potentially exist.

    Published: 6 Jun 2017