CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2017-8313

    Last Modified: 20 Apr 2025

    Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process via a crafted subtitles file.

    Published: 23 May 2017
    5.5
    Medium

    CVE-2017-8314

    Last Modified: 20 Apr 2025

    Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.

    Published: 23 May 2017
    5.5
    Medium

    CVE-2017-8310

    Last Modified: 20 Apr 2025

    Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond allocated memory and potentially crash the process (causing a denial of service) via a crafted subtitles file.

    Published: 23 May 2017
    7.3
    High

    CVE-2017-0373

    Last Modified: 20 Apr 2025

    The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "use lib" line, which allows remote attackers to have an unspecified impact via a crafted Debian package file.

    Published: 23 May 2017
    7.8
    High

    CVE-2017-0374

    Last Modified: 20 Apr 2025

    lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a crafted model in the current working directory, related to use of . with the INC array.

    Published: 23 May 2017
    4.8
    Medium

    CVE-2017-3128

    Last Modified: 20 Apr 2025

    A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or commands via the policy global-label parameter.

    Published: 23 May 2017
    8.3
    High

    CVE-2017-2783

    Last Modified: 20 Apr 2025

    An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter that is shipped with MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious xls file to trigger this vulnerability.

    Published: 23 May 2017
    8.3
    High

    CVE-2017-2793

    Last Modified: 20 Apr 2025

    An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

    Published: 23 May 2017
    8.3
    High

    CVE-2017-2797

    Last Modified: 20 Apr 2025

    An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6.

    Published: 23 May 2017
    8.3
    High

    CVE-2017-2794

    Last Modified: 20 Apr 2025

    An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted PPT file can cause a stack corruption resulting in arbitrary code execution. An attacker can send/provide malicious PPT file to trigger this vulnerability.

    Published: 23 May 2017
    9.8
    Critical

    CVE-2017-6131

    Last Modified: 20 Apr 2025

    In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default administrative password which could be used to remotely log into the BIG-IP system. The impacted administrative account is the Azure instance administrative user that was created at deployment. The root and admin accounts are not vulnerable. An attacker may be able to remotely access the BIG-IP host via SSH.

    Published: 23 May 2017
    7.5
    High

    CVE-2017-9212

    Last Modified: 20 Apr 2025

    The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.

    Published: 23 May 2017
    6.7
    Medium

    CVE-2017-5965

    Last Modified: 20 Apr 2025

    The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP code by creating a ZIP archive in which a .asp file has a ..\ in its pathname, visiting sitecore/shell/applications/install/dialogs/Upload%20Package/UploadPackage2.aspx to upload this archive and extract its contents, and visiting a URI under sitecore/ to execute the .asp file.

    Published: 23 May 2017
    4.9
    Medium

    CVE-2017-5966

    Last Modified: 20 Apr 2025

    Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.

    Published: 23 May 2017
    9.1
    Critical

    CVE-2015-5609

    Last Modified: 20 Apr 2025

    Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-5682

    Last Modified: 20 Apr 2025

    upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-6586

    Last Modified: 20 Apr 2025

    The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict processing of mDNS unicast queries to the link local network.

    Published: 23 May 2017
    9.8
    Critical

    CVE-2015-4455

    Last Modified: 20 Apr 2025

    Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

    Published: 23 May 2017
    6.1
    Medium

    CVE-2015-5381

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in program/include/rcmail.php in Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the _mbox parameter to the default URI.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2015-5382

    Last Modified: 20 Apr 2025

    program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via the _alt parameter when uploading a vCard.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-5383

    Last Modified: 20 Apr 2025

    Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) logs directory.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-5401

    Last Modified: 20 Apr 2025

    Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database crash) via a malformed CONFIG REQUEST message.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-5468

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-5469

    Last Modified: 20 Apr 2025

    Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.

    Published: 23 May 2017
    8.1
    High

    CVE-2015-6817

    Last Modified: 20 Apr 2025

    PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.

    Published: 23 May 2017
    8.8
    High

    CVE-2017-8913

    Last Modified: 20 Apr 2025

    The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.default, aka SAP Security Note 2386873.

    Published: 23 May 2017
    7.5
    High

    CVE-2017-8915

    Last Modified: 20 Apr 2025

    sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to cause a denial of service (assertion failure and service crash) by pushing a package with a filename containing a $ (dollar sign) or % (percent) character, aka SAP Security Note 2407694.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9206

    Last Modified: 20 Apr 2025

    The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-1529

    Last Modified: 20 Apr 2025

    Integer overflow in soundtrigger/ISoundTriggerHwService.cpp in Android allows attacks to cause a denial of service via unspecified vectors.

    Published: 23 May 2017
    6.7
    Medium

    CVE-2015-4045

    Last Modified: 20 Apr 2025

    The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.

    Published: 23 May 2017
    7.2
    High

    CVE-2015-4046

    Last Modified: 20 Apr 2025

    The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-4054

    Last Modified: 20 Apr 2025

    PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.

    Published: 23 May 2017
    7.5
    High

    CVE-2015-4704

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php.

    Published: 23 May 2017
    7.8
    High

    CVE-2015-8089

    Last Modified: 20 Apr 2025

    The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows local users to read or write to arbitrary kernel memory locations and consequently cause a denial of service (system crash) or gain privileges via a crafted application.

    Published: 23 May 2017
    6.1
    Medium

    CVE-2015-8477

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Redmine before 2.6.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving flash message rendering.

    Published: 23 May 2017
    7.5
    High

    CVE-2016-10073

    Last Modified: 20 Apr 2025

    The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

    Published: 23 May 2017
    7.8
    High

    CVE-2016-1876

    Last Modified: 20 Apr 2025

    The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.

    Published: 23 May 2017
    7.8
    High

    CVE-2016-5735

    Last Modified: 20 Apr 2025

    Integer overflow in the rwpng_read_image24_libpng function in rwpng.c in pngquant 2.7.0 allows remote attackers to have unspecified impact via a crafted PNG file, which triggers a buffer overflow.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9207

    Last Modified: 20 Apr 2025

    The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image, related to imagew-jpeg.c.

    Published: 23 May 2017
    5.4
    Medium

    CVE-2017-5870

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.

    Published: 23 May 2017
    9.8
    Critical

    CVE-2017-6813

    Last Modified: 20 Apr 2025

    A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.

    Published: 23 May 2017
    6.1
    Medium

    CVE-2017-7288

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9201

    Last Modified: 20 Apr 2025

    imagew-cmd.c:850:46 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted image, related to imagew-api.c.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9202

    Last Modified: 20 Apr 2025

    imagew-cmd.c:854:45 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted image, related to imagew-api.c.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9203

    Last Modified: 20 Apr 2025

    imagew-main.c:960:12 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (buffer underflow) via a crafted image, related to imagew-bmp.c.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9204

    Last Modified: 20 Apr 2025

    The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c.

    Published: 23 May 2017
    6.5
    Medium

    CVE-2017-9205

    Last Modified: 20 Apr 2025

    The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted image, related to imagew-jpeg.c.

    Published: 23 May 2017
    9.8
    Critical

    CVE-2017-6821

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.

    Published: 23 May 2017
    8.3
    High

    CVE-2017-8914

    Last Modified: 20 Apr 2025

    sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.

    Published: 23 May 2017
    5.9
    Medium

    CVE-2017-8932

    Last Modified: 20 Apr 2025

    A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.

    Published: 23 May 2017