CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2017-5081

    Last Modified: 20 Apr 2025

    Lack of verification of an extension's locale folder in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed an attacker with local write access to modify extensions by modifying extension files.

    Published: 5 Jun 2017
    5.5
    Medium

    CVE-2017-5082

    Last Modified: 20 Apr 2025

    Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacker to take screen shots of credit card information via a crafted HTML page.

    Published: 5 Jun 2017
    6.1
    Medium

    CVE-2017-8439

    Last Modified: 20 Apr 2025

    Kibana version 5.4.0 was affected by a Cross Site Scripting (XSS) bug in the Time Series Visual Builder. This bug could allow an attacker to obtain sensitive information from Kibana users.

    Published: 5 Jun 2017
    6.1
    Medium

    CVE-2017-8440

    Last Modified: 20 Apr 2025

    Starting in version 5.3.0, Kibana had a cross-site scripting (XSS) vulnerability in the Discover page that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.

    Published: 5 Jun 2017
    8
    High

    CVE-2017-5074

    Last Modified: 20 Apr 2025

    A use after free in Chrome Apps in Google Chrome prior to 59.0.3071.86 for Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page, related to Bluetooth.

    Published: 5 Jun 2017
    4.3
    Medium

    CVE-2017-5075

    Last Modified: 20 Apr 2025

    Inappropriate implementation in CSP reporting in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to obtain the value of url fragments via a crafted HTML page.

    Published: 5 Jun 2017
    8.8
    High

    CVE-2017-5077

    Last Modified: 20 Apr 2025

    Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 5 Jun 2017
    8.8
    High

    CVE-2017-5078

    Last Modified: 20 Apr 2025

    Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument.

    Published: 5 Jun 2017
    4.3
    Medium

    CVE-2017-5079

    Last Modified: 20 Apr 2025

    Inappropriate implementation in Blink in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to display UI on a non attacker controlled tab via a crafted HTML page.

    Published: 5 Jun 2017
    6.5
    Medium

    CVE-2017-5086

    Last Modified: 20 Apr 2025

    Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

    Published: 5 Jun 2017
    4.4
    Medium

    CVE-2017-7516

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1197. Reason: This candidate is a duplicate of CVE-2015-1197. Notes: All CVE users should reference CVE-2015-1197 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 5 Jun 2017
    5.5
    Medium

    CVE-2014-9983

    Last Modified: 20 Apr 2025

    Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

    Published: 4 Jun 2017
    7.5
    High

    CVE-2017-9428

    Last Modified: 20 Apr 2025

    A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory parameter.

    Published: 4 Jun 2017
    8.8
    High

    CVE-2017-9427

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/developer/modules/designer/ and the injection is visible at admin/dashboard/vitals-statistics/integrity/check/?external=true.

    Published: 4 Jun 2017
    6.5
    Medium

    CVE-2017-11524

    Last Modified: 20 Apr 2025

    The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.

    Published: 4 Jun 2017
    6.5
    Medium

    CVE-2017-9416

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.

    Published: 3 Jun 2017
    9.8
    Critical

    CVE-2017-9417

    Last Modified: 20 Apr 2025

    Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

    Published: 3 Jun 2017
    6.1
    Medium

    CVE-2012-6705

    Last Modified: 20 Apr 2025

    Cross Site Scripting (XSS) exists in Jamroom before 4.2.7 via the Status Update field.

    Published: 3 Jun 2017
    7.5
    High

    CVE-2016-8231

    Last Modified: 20 Apr 2025

    In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.

    Published: 3 Jun 2017
    7.8
    High

    CVE-2016-8228

    Last Modified: 20 Apr 2025

    In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.

    Published: 3 Jun 2017
    8.8
    High

    CVE-2016-8229

    Last Modified: 20 Apr 2025

    A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server used by the system where LSB is installed.

    Published: 3 Jun 2017
    7.5
    High

    CVE-2016-8230

    Last Modified: 20 Apr 2025

    In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and product name to Lenovo's servers.

    Published: 3 Jun 2017
    3.3
    Low

    CVE-2017-3741

    Last Modified: 20 Apr 2025

    In the Lenovo Power Management driver before 1.67.12.24, a local user may alter the trackpoint's firmware and stop the trackpoint from functioning correctly. This issue only affects ThinkPad X1 Carbon 5th generation.

    Published: 3 Jun 2017
    5.5
    Medium

    CVE-2017-3740

    Last Modified: 20 Apr 2025

    In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.

    Published: 3 Jun 2017
    6.5
    Medium

    CVE-2017-0896

    Last Modified: 20 Apr 2025

    Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat application server that allowed an authenticated user to invite other users to join a Zulip organization even if the organization was configured to prevent this.

    Published: 2 Jun 2017
    7.5
    High

    CVE-2017-7669

    Last Modified: 20 Apr 2025

    In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.

    Published: 2 Jun 2017
    8.8
    High

    CVE-2017-9379

    Last Modified: 20 Apr 2025

    Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.

    Published: 2 Jun 2017
    8.8
    High

    CVE-2017-9380

    Last Modified: 20 Apr 2025

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

    Published: 2 Jun 2017
    6.5
    Medium

    CVE-2017-9378

    Last Modified: 20 Apr 2025

    BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted.

    Published: 2 Jun 2017
    5.3
    Medium

    CVE-2017-6039

    Last Modified: 20 Apr 2025

    A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.

    Published: 2 Jun 2017
    7.5
    High

    CVE-2017-9372

    Last Modified: 20 Apr 2025

    PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP packet with a crafted CSeq header in conjunction with a Via header that lacks a branch parameter.

    Published: 2 Jun 2017
    7.5
    High

    CVE-2017-9358

    Last Modified: 20 Apr 2025

    A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13-cert4, which can be triggered by sending specially crafted SCCP packets causing an infinite loop and leading to memory exhaustion (by message logging in that loop).

    Published: 2 Jun 2017
    9.8
    Critical

    CVE-2017-9363

    Last Modified: 20 Apr 2025

    Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.

    Published: 2 Jun 2017
    4.8
    Medium

    CVE-2017-9366

    Last Modified: 20 Apr 2025

    Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter.

    Published: 2 Jun 2017
    9.8
    Critical

    CVE-2017-9360

    Last Modified: 20 Apr 2025

    WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.

    Published: 2 Jun 2017
    6.1
    Medium

    CVE-2017-9361

    Last Modified: 20 Apr 2025

    WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.

    Published: 2 Jun 2017
    7.5
    High

    CVE-2017-9359

    Last Modified: 20 Apr 2025

    The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Published: 2 Jun 2017
    8.8
    High

    CVE-2017-9365

    Last Modified: 20 Apr 2025

    CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.

    Published: 2 Jun 2017
    9.8
    Critical

    CVE-2017-9364

    Last Modified: 20 Apr 2025

    Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.

    Published: 2 Jun 2017
    5.3
    Medium

    CVE-2017-7539

    Last Modified: 21 Nov 2024

    An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected data during connection negotiation. A remote user or process could use this flaw to crash the qemu-nbd server resulting in denial of service.

    Published: 2 Jun 2017
    5.5
    Medium

    CVE-2017-9605

    Last Modified: 20 Apr 2025

    The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.11.4 defines a backup_handle variable but does not give it an initial value. If one attempts to create a GB surface, with a previously allocated DMA buffer to be used as a backup buffer, the backup_handle variable does not get written to and is then later returned to user space, allowing local users to obtain sensitive information from uninitialized kernel memory via a crafted ioctl call.

    Published: 2 Jun 2017
    8.2
    High

    CVE-2017-1000368

    Last Modified: 20 Apr 2025

    Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command execution.

    Published: 2 Jun 2017
    Unknown

    CVE-2016-3073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-3079. Reason: This candidate is a reservation duplicate of CVE-2016-3079. Notes: All CVE users should reference CVE-2016-3079 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jun 2017
    9.8
    Critical

    CVE-2015-0936

    Last Modified: 20 Apr 2025

    Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.

    Published: 1 Jun 2017
    9.8
    Critical

    CVE-2015-5473

    Last Modified: 20 Apr 2025

    Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with SYSTEM privileges via unspecified parameters to (3) uploadCloning.html, (4) fileupload.html, (5) uploadFirmware.html, or (6) upload/driver.

    Published: 1 Jun 2017
    7.8
    High

    CVE-2015-6531

    Last Modified: 20 Apr 2025

    Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.

    Published: 1 Jun 2017
    6.1
    Medium

    CVE-2017-7384

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter.

    Published: 1 Jun 2017
    6.5
    Medium

    CVE-2017-7999

    Last Modified: 20 Apr 2025

    Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vectors.

    Published: 1 Jun 2017
    6.1
    Medium

    CVE-2017-3127

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.

    Published: 1 Jun 2017
    5.4
    Medium

    CVE-2017-9331

    Last Modified: 20 Apr 2025

    The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meeting description parameter.

    Published: 1 Jun 2017