CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-9214

    Last Modified: 20 Apr 2025

    In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.

    Published: 20 May 2017
    6.5
    Medium

    CVE-2017-9093

    Last Modified: 20 Apr 2025

    The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.

    Published: 19 May 2017
    6.5
    Medium

    CVE-2017-9094

    Last Modified: 20 Apr 2025

    The lzw_add_to_dict function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.

    Published: 19 May 2017
    7.5
    High

    CVE-2017-9090

    Last Modified: 20 Apr 2025

    reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].

    Published: 19 May 2017
    7.5
    High

    CVE-2017-9091

    Last Modified: 20 Apr 2025

    /admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].

    Published: 19 May 2017
    7.8
    High

    CVE-2017-7968

    Last Modified: 20 Apr 2025

    An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This could allow an authenticated user to escalate his or her privileges.

    Published: 19 May 2017
    7.1
    High

    CVE-2017-4979

    Last Modified: 20 Apr 2025

    EMC Isilon OneFS 8.0.1.0, OneFS 8.0.0.0 - 8.0.0.2, OneFS 7.2.1.0 - 7.2.1.3, and OneFS 7.2.0.x is affected by an NFS export vulnerability. Under certain conditions, after upgrading a cluster from OneFS 7.1.1.x or earlier, users may have unexpected levels of access to some NFS exports.

    Published: 19 May 2017
    8.8
    High

    CVE-2017-9080

    Last Modified: 20 Apr 2025

    PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.

    Published: 19 May 2017
    5.4
    Medium

    CVE-2017-4978

    Last Modified: 20 Apr 2025

    EMC RSA Adaptive Authentication (On-Premise) versions prior to 7.3 P2 (exclusive) contains a fix for a cross-site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 19 May 2017
    8.8
    High

    CVE-2017-9078

    Last Modified: 20 Apr 2025

    The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.

    Published: 19 May 2017
    4.7
    Medium

    CVE-2017-9079

    Last Modified: 20 Apr 2025

    Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.

    Published: 19 May 2017
    8.8
    High

    CVE-2017-6048

    Last Modified: 20 Apr 2025

    A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataLogger V5.37c-1.43c and prior, SenNet Solar Datalogger V5.03-1.56a and prior, and SenNet Multitask Meter V5.21a-1.18b and prior. Successful exploitation of this vulnerability could result in the attacker breaking out of the jailed shell and gaining full access to the system.

    Published: 19 May 2017
    9.8
    Critical

    CVE-2017-5173

    Last Modified: 20 Apr 2025

    An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not properly neutralized, an attacker can call multiple parameters that can allow access to the root level operating system which could allow remote code execution.

    Published: 19 May 2017
    9.8
    Critical

    CVE-2017-5174

    Last Modified: 20 Apr 2025

    An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control that may allow remote code execution.

    Published: 19 May 2017
    9.8
    Critical

    CVE-2017-6025

    Last Modified: 20 Apr 2025

    A Stack Buffer Overflow issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A malicious user could overflow the stack buffer by providing overly long strings to functions that handle the XML. Because the function does not verify string size before copying to memory, the attacker may then be able to crash the application or run arbitrary code.

    Published: 19 May 2017
    9.8
    Critical

    CVE-2017-6027

    Last Modified: 20 Apr 2025

    An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2.3 and prior. A specially crafted web server request may allow the upload of arbitrary files (with a dangerous type) to the CODESYS Web Server without authorization which may allow remote code execution.

    Published: 19 May 2017
    6.6
    Medium

    CVE-2017-7907

    Last Modified: 20 Apr 2025

    An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could cause a denial of service or disclose file contents from a server or connected network.

    Published: 19 May 2017
    7.5
    High

    CVE-2017-7935

    Last Modified: 20 Apr 2025

    A Resource Exhaustion issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may compromise the device's availability by performing multiple initial VPN requests.

    Published: 19 May 2017
    4
    Medium

    CVE-2017-7937

    Last Modified: 20 Apr 2025

    An Improper Authentication issue was discovered in Phoenix Contact GmbH mGuard firmware versions 8.3.0 to 8.4.2. An attacker may be able to gain unauthorized access to the user firewall when RADIUS servers are unreachable.

    Published: 19 May 2017
    7
    High

    CVE-2017-5176

    Last Modified: 20 Apr 2025

    A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.

    Published: 19 May 2017
    7.5
    High

    CVE-2017-5177

    Last Modified: 20 Apr 2025

    A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability has been identified, where an attacker with a specially crafted packet could overflow the fixed length buffer. This could allow remote code execution.

    Published: 19 May 2017
    7.3
    High

    CVE-2017-6016

    Last Modified: 20 Apr 2025

    An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improper Access Control vulnerability has been identified, which may allow an authenticated user to modify application files to escalate privileges.

    Published: 19 May 2017
    5.5
    Medium

    CVE-2017-9242

    Last Modified: 20 Apr 2025

    The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb data structure may occur, which allows local users to cause a denial of service (system crash) via crafted system calls.

    Published: 19 May 2017
    Unknown

    CVE-2017-9073

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-0176. Reason: This candidate is a reservation duplicate of CVE-2017-0176. Notes: All CVE users should reference CVE-2017-0176 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 May 2017
    9.8
    Critical

    CVE-2017-6622

    Last Modified: 20 Apr 2025

    A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraints in certain HTTP request methods, which could allow access to files via the web interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to the targeted application. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases prior to 12.1. Cisco Bug IDs: CSCvc98724.

    Published: 18 May 2017
    7.5
    High

    CVE-2017-6652

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by using directory traversal techniques to read files within the Cisco TelePresence IX5000 Series filesystem. This vulnerability affects Cisco TelePresence IX5000 Series devices running software version 8.2.0. Cisco Bug IDs: CSCvc52325.

    Published: 18 May 2017
    7.2
    High

    CVE-2017-3980

    Last Modified: 20 Apr 2025

    A directory traversal vulnerability in the ePO Extension in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, and 5.1.3 and earlier allows remote authenticated users to execute a command of their choice via an authenticated ePO session.

    Published: 18 May 2017
    7.5
    High

    CVE-2017-6621

    Last Modified: 20 Apr 2025

    A vulnerability in the web interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to access sensitive data. The attacker could use this information to conduct additional reconnaissance attacks. The vulnerability is due to insufficient protection of sensitive data when responding to an HTTP request on the web interface. An attacker could exploit the vulnerability by sending a crafted HTTP request to the application to access specific system files. An exploit could allow the attacker to obtain sensitive information about the application which could include user credentials. This vulnerability affects Cisco Prime Collaboration Provisioning Software Releases 10.6 through 11.5. Cisco Bug IDs: CSCvc99626.

    Published: 18 May 2017
    7.8
    High

    CVE-2017-6623

    Last Modified: 20 Apr 2025

    A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to root. The vulnerability is due to incorrect sudoers permissions on the script file. An attacker could exploit this vulnerability by authenticating to the device and providing crafted user input at the CLI, using this script file to escalate their privilege level and execute commands as root. A successful exploit could allow the attacker to acquire root-level privileges and take full control of the appliance. The user has to be logged-in to the device with valid credentials for a specific set of users. The Cisco Policy Suite application is vulnerable when running software versions 10.0.0, 10.1.0, or 11.0.0. Cisco Bug IDs: CSCvc07366.

    Published: 18 May 2017
    6.1
    Medium

    CVE-2017-9072

    Last Modified: 20 Apr 2025

    Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm.

    Published: 18 May 2017
    7
    High

    CVE-2017-9067

    Last Modified: 20 Apr 2025

    In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.

    Published: 18 May 2017
    8.8
    High

    CVE-2017-9069

    Last Modified: 20 Apr 2025

    In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.

    Published: 18 May 2017
    5.4
    Medium

    CVE-2017-9070

    Last Modified: 20 Apr 2025

    In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.

    Published: 18 May 2017
    4.7
    Medium

    CVE-2017-9071

    Last Modified: 20 Apr 2025

    In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.

    Published: 18 May 2017
    6.1
    Medium

    CVE-2017-9068

    Last Modified: 20 Apr 2025

    In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.

    Published: 18 May 2017
    6.1
    Medium

    CVE-2017-9061

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

    Published: 18 May 2017
    8.6
    High

    CVE-2017-9062

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, there is improper handling of post meta data values in the XML-RPC API.

    Published: 18 May 2017
    6.1
    Medium

    CVE-2017-9063

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability related to the Customizer exists, involving an invalid customization session.

    Published: 18 May 2017
    8.8
    High

    CVE-2017-9064

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, a Cross Site Request Forgery (CSRF) vulnerability exists in the filesystem credentials dialog because a nonce is not required for updating credentials.

    Published: 18 May 2017
    7.5
    High

    CVE-2017-9065

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

    Published: 18 May 2017
    8.6
    High

    CVE-2017-9066

    Last Modified: 20 Apr 2025

    In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

    Published: 18 May 2017
    6.5
    Medium

    CVE-2017-7433

    Last Modified: 20 Apr 2025

    An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the attack can be performed without authentication if Guest access is enabled (Guest access is disabled by default).

    Published: 18 May 2017
    9.8
    Critical

    CVE-2017-6195

    Last Modified: 20 Apr 2025

    Ipswitch MOVEit Transfer (formerly DMZ) allows pre-authentication blind SQL injection. The fixed versions are MOVEit Transfer 2017 9.0.0.201, MOVEit DMZ 8.3.0.30, and MOVEit DMZ 8.2.0.20.

    Published: 18 May 2017
    5.9
    Medium

    CVE-2017-9045

    Last Modified: 20 Apr 2025

    The Google I/O 2017 application before 5.1.4 for Android downloads multiple .json files from http://storage.googleapis.com without SSL, which makes it easier for man-in-the-middle attackers to spoof Feed and Schedule data by creating a modified blocks_v4.json file.

    Published: 18 May 2017
    7.5
    High

    CVE-2017-8338

    Last Modified: 20 Apr 2025

    A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.

    Published: 18 May 2017
    4.6
    Medium

    CVE-2017-8769

    Last Modified: 20 Apr 2025

    Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion to occur upon chat deletion, or who expect encryption (consistent with the application's use of an encrypted database to store chat text). NOTE: the vendor reportedly indicates that they do not "consider these to be security issues" because a user may legitimately want to preserve any file for use "in other apps like the Google Photos gallery" regardless of whether its associated chat is deleted

    Published: 18 May 2017
    9.8
    Critical

    CVE-2017-9058

    Last Modified: 20 Apr 2025

    In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

    Published: 18 May 2017
    9.8
    Critical

    CVE-2017-9051

    Last Modified: 20 Apr 2025

    libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.

    Published: 18 May 2017
    6.5
    Medium

    CVE-2017-9083

    Last Modified: 20 Apr 2025

    poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.

    Published: 18 May 2017
    9.8
    Critical

    CVE-2017-7503

    Last Modified: 20 Apr 2025

    It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use this flaw to launch DoS or SSRF attacks, or read files from the server where EAP is deployed.

    Published: 18 May 2017