CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-9336

    Last Modified: 20 Apr 2025

    The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.

    Published: 1 Jun 2017
    6.1
    Medium

    CVE-2017-9337

    Last Modified: 20 Apr 2025

    The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9334

    Last Modified: 20 Apr 2025

    An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of service by passing an improper list to an application that calls "length" on it.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-11411

    Last Modified: 20 Apr 2025

    In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by adding length validation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9350.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9343

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9350

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.

    Published: 1 Jun 2017
    5.5
    Medium

    CVE-2017-0641

    Last Modified: 20 Apr 2025

    A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9345

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9346

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9347

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9348

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9349

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9352

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9353

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9354

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an IPv4 address.

    Published: 1 Jun 2017
    5.9
    Medium

    CVE-2017-9526

    Last Modified: 20 Apr 2025

    In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover the long-term secret key. 1.7.7 makes a cipher/ecc-eddsa.c change to store this session key in secure memory, to ensure that constant-time point operations are used in the MPI library.

    Published: 1 Jun 2017
    5.5
    Medium

    CVE-2017-18241

    Last Modified: 21 Nov 2024

    fs/f2fs/segment.c in the Linux kernel before 4.13 allows local users to cause a denial of service (NULL pointer dereference and panic) by using a noflush_merge option that triggers a NULL value for a flush_cmd_control data structure.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9344

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.

    Published: 1 Jun 2017
    7.5
    High

    CVE-2017-9351

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.

    Published: 1 Jun 2017
    Unknown

    CVE-2016-10373

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10214. Reason: This candidate is a reservation duplicate of CVE-2016-10214. Notes: All CVE users should reference CVE-2016-10214 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 May 2017
    6.7
    Medium

    CVE-2017-5688

    Last Modified: 20 Apr 2025

    There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.

    Published: 31 May 2017
    5.5
    Medium

    CVE-2017-4897

    Last Modified: 20 Apr 2025

    VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim to download a specially crafted RDP file through DaaS client by clicking on a malicious link.

    Published: 31 May 2017
    7.5
    High

    CVE-2017-9304

    Last Modified: 20 Apr 2025

    libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.

    Published: 31 May 2017
    8.8
    High

    CVE-2017-8402

    Last Modified: 20 Apr 2025

    PivotX 2.3.11 allows remote authenticated users to execute arbitrary PHP code via vectors involving an upload of a .htaccess file.

    Published: 31 May 2017
    6.5
    Medium

    CVE-2017-8782

    Last Modified: 20 Apr 2025

    The readString function in util/read.c and util/old/read.c in libming 0.4.8 allows remote attackers to cause a denial of service via a large file that is mishandled by listswf, listaction, etc. This occurs because of an integer overflow that leads to a memory allocation error.

    Published: 31 May 2017
    6.1
    Medium

    CVE-2017-9306

    Last Modified: 20 Apr 2025

    inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.

    Published: 31 May 2017
    6.1
    Medium

    CVE-2017-9305

    Last Modified: 20 Apr 2025

    lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newsletter.php.

    Published: 31 May 2017
    6.5
    Medium

    CVE-2017-9307

    Last Modified: 20 Apr 2025

    SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.

    Published: 31 May 2017
    5.9
    Medium

    CVE-2017-4971

    Last Modified: 8 Sept 2026

    An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.

    Published: 31 May 2017
    6.5
    Medium

    CVE-2017-2639

    Last Modified: 21 Nov 2024

    It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenShift. This would allow an attacker to spoof RHEV or OpenShift systems and potentially harvest sensitive information from CloudForms.

    Published: 31 May 2017
    7.5
    High

    CVE-2016-3083

    Last Modified: 20 Apr 2025

    Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x before 2.0.1 doesn't seem to be verifying the common name attribute of the certificate. In this way, if a JDBC client sends an SSL request to server abc.com, and the server responds with a valid certificate (certified by CA) but issued to xyz.com, the client will accept that as a valid certificate and the SSL handshake will go through.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-2300

    Last Modified: 20 Apr 2025

    On Juniper Networks SRX Series Services Gateways chassis clusters running Junos OS 12.1X46 prior to 12.1X46-D65, 12.3X48 prior to 12.3X48-D40, 12.3X48 prior to 12.3X48-D60, flowd daemon on the primary node of an SRX Series chassis cluster may crash and restart when attempting to synchronize a multicast session created via crafted multicast packets.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-2303

    Last Modified: 20 Apr 2025

    On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D50, 12.1X47 prior to 12.1X47-D40, 12.3 prior to 12.3R13, 12.3X48 prior to 12.3X48-D30, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R5, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D30 or 15.1X49-D40, 15.1X53 prior to 15.1X53-D35, and where RIP is enabled, certain RIP advertisements received by the router may cause the RPD daemon to crash resulting in a denial of service condition.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-2304

    Last Modified: 20 Apr 2025

    Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X53-D40, 15.1 prior to 15.1R2, do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is also known as 'Etherleak'

    Published: 30 May 2017
    8.8
    High

    CVE-2017-2305

    Last Modified: 20 Apr 2025

    On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create privileged users, allowing privilege escalation.

    Published: 30 May 2017
    8.8
    High

    CVE-2017-2306

    Last Modified: 20 Apr 2025

    On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can execute code on the device.

    Published: 30 May 2017
    5.9
    Medium

    CVE-2017-2309

    Last Modified: 20 Apr 2025

    On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricted web services are accessible over the network. This represents an information leak risk.

    Published: 30 May 2017
    5.3
    Medium

    CVE-2017-2310

    Last Modified: 20 Apr 2025

    A firewall bypass vulnerability in the host based firewall of Juniper Networks Junos Space versions prior to 16.1R1 may permit certain crafted packets, representing a network integrity risk.

    Published: 30 May 2017
    5.3
    Medium

    CVE-2017-2311

    Last Modified: 20 Apr 2025

    On Juniper Networks Junos Space versions prior to 16.1R1, an unauthenticated remote attacker with network access to Junos space device can easily create a denial of service condition.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-2301

    Last Modified: 20 Apr 2025

    On Juniper Networks products or platforms running Junos OS 11.4 prior to 11.4R13-S3, 12.1X46 prior to 12.1X46-D60, 12.3 prior to 12.3R12-S2 or 12.3R13, 12.3X48 prior to 12.3X48-D40, 13.2X51 prior to 13.2X51-D40, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D12 or 14.1X53-D35, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R7, 15.1 prior to 15.1F6 or 15.1R3, 15.1X49 prior to 15.1X49-D60, 15.1X53 prior to 15.1X53-D30 and DHCPv6 enabled, when a crafted DHCPv6 packet is received from a subscriber, jdhcpd daemon crashes and restarts. Repeated crashes of the jdhcpd process may constitute an extended denial of service condition for subscribers attempting to obtain IPv6 addresses.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-2302

    Last Modified: 20 Apr 2025

    On Juniper Networks products or platforms running Junos OS 12.1X46 prior to 12.1X46-D55, 12.1X47 prior to 12.1X47-D45, 12.3R13 prior to 12.3R13, 12.3X48 prior to 12.3X48-D35, 13.3 prior to 13.3R10, 14.1 prior to 14.1R8, 14.1X53 prior to 14.1X53-D40, 14.1X55 prior to 14.1X55-D35, 14.2 prior to 14.2R6, 15.1 prior to 15.1F2 or 15.1R1, 15.1X49 prior to 15.1X49-D20 where the BGP add-path feature is enabled with 'send' option or with both 'send' and 'receive' options, a network based attacker can cause the Junos OS rpd daemon to crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition.

    Published: 30 May 2017
    6.1
    Medium

    CVE-2017-2307

    Last Modified: 20 Apr 2025

    A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space.

    Published: 30 May 2017
    6.5
    Medium

    CVE-2017-2308

    Last Modified: 20 Apr 2025

    An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbitrary files on the device.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-9023

    Last Modified: 3 Dec 2025

    The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allows remote attackers to cause a denial of service (infinite loop) via a crafted certificate.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-9022

    Last Modified: 3 Dec 2025

    The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.

    Published: 30 May 2017
    6.4
    Medium

    CVE-2017-1000367

    Last Modified: 20 Apr 2025

    Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

    Published: 30 May 2017
    7.5
    High

    CVE-2017-7502

    Last Modified: 20 Apr 2025

    Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker.

    Published: 30 May 2017
    6.1
    Medium

    CVE-2017-9303

    Last Modified: 20 Apr 2025

    Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-controlled host.

    Published: 29 May 2017
    7.2
    High

    CVE-2016-10378

    Last Modified: 20 Apr 2025

    e107 2.1.1 allows SQL injection by remote authenticated administrators via the pagelist parameter to e107_admin/menus.php, related to the menuSaveVisibility function.

    Published: 29 May 2017
    7.2
    High

    CVE-2016-10379

    Last Modified: 20 Apr 2025

    The VirtueMart com_virtuemart component 3.0.14 for Joomla! allows SQL injection by remote authenticated administrators via the virtuemart_paymentmethod_id or virtuemart_shipmentmethod_id parameter to administrator/index.php.

    Published: 29 May 2017