CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-10238

    Last Modified: 20 Apr 2025

    In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.

    Published: 16 May 2017
    7.8
    High

    CVE-2016-10239

    Last Modified: 20 Apr 2025

    In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer over-read vulnerability could potentially occur.

    Published: 16 May 2017
    7.8
    High

    CVE-2014-9933

    Last Modified: 20 Apr 2025

    Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not have access.

    Published: 16 May 2017
    7.8
    High

    CVE-2014-9935

    Last Modified: 20 Apr 2025

    In TrustZone an integer overflow vulnerability leading to a buffer overflow could potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7
    High

    CVE-2014-9936

    Last Modified: 20 Apr 2025

    In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7.8
    High

    CVE-2014-9937

    Last Modified: 20 Apr 2025

    In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7.8
    High

    CVE-2015-9003

    Last Modified: 20 Apr 2025

    In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7.8
    High

    CVE-2015-9002

    Last Modified: 20 Apr 2025

    In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7.8
    High

    CVE-2015-8999

    Last Modified: 20 Apr 2025

    In TrustZone a buffer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel while loading an ELF file.

    Published: 16 May 2017
    7.8
    High

    CVE-2015-8995

    Last Modified: 20 Apr 2025

    In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7
    High

    CVE-2015-8996

    Last Modified: 20 Apr 2025

    In TrustZone a time-of-check time-of-use race condition could potentially exist in a QFPROM routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7
    High

    CVE-2015-8997

    Last Modified: 20 Apr 2025

    In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    7
    High

    CVE-2016-10242

    Last Modified: 20 Apr 2025

    A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.

    Published: 16 May 2017
    8.8
    High

    CVE-2017-7952

    Last Modified: 20 Apr 2025

    INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.

    Published: 16 May 2017
    5.4
    Medium

    CVE-2017-7953

    Last Modified: 20 Apr 2025

    INFOR EAM V11.0 Build 201410 has XSS via comment fields.

    Published: 16 May 2017
    4.5
    Medium

    CVE-2017-8382

    Last Modified: 20 Apr 2025

    admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user accounts.

    Published: 16 May 2017
    7.5
    High

    CVE-2017-9735

    Last Modified: 20 Apr 2025

    Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

    Published: 16 May 2017
    7.8
    High

    CVE-2017-7493

    Last Modified: 20 Apr 2025

    Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing virtfs metadata files in mapped-file security mode. A guest user could use this flaw to escalate their privileges inside guest.

    Published: 16 May 2017
    7.8
    High

    CVE-2017-9074

    Last Modified: 20 Apr 2025

    The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid option, which allows local users to cause a denial of service (out-of-bounds read and BUG) or possibly have unspecified other impact via crafted socket and send system calls.

    Published: 16 May 2017
    2.7
    Low

    CVE-2016-5979

    Last Modified: 20 Apr 2025

    IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM X-Force ID: 116379.

    Published: 15 May 2017
    4.3
    Medium

    CVE-2016-9735

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781,

    Published: 15 May 2017
    6.5
    Medium

    CVE-2016-9750

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8938

    Last Modified: 20 Apr 2025

    The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8939

    Last Modified: 20 Apr 2025

    The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8942

    Last Modified: 20 Apr 2025

    The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    6.5
    Medium

    CVE-2017-7479

    Last Modified: 20 Apr 2025

    OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over resulting into Denial of Service of server by authenticated attacker.

    Published: 15 May 2017
    7.5
    High

    CVE-2017-7478

    Last Modified: 20 Apr 2025

    OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

    Published: 15 May 2017
    Unknown

    CVE-2017-7498

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8934. Reason: This candidate is a reservation duplicate of CVE-2017-8934. Notes: All CVE users should reference CVE-2017-8934 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 May 2017
    Unknown

    CVE-2017-7499

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8933. Reason: This candidate is a reservation duplicate of CVE-2017-8933. Notes: All CVE users should reference CVE-2017-8933 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8937

    Last Modified: 20 Apr 2025

    The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    7.8
    High

    CVE-2017-8926

    Last Modified: 20 Apr 2025

    Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.

    Published: 15 May 2017
    7.8
    High

    CVE-2017-8927

    Last Modified: 20 Apr 2025

    Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8935

    Last Modified: 20 Apr 2025

    The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8936

    Last Modified: 20 Apr 2025

    The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8940

    Last Modified: 20 Apr 2025

    The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8941

    Last Modified: 20 Apr 2025

    The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    5.9
    Medium

    CVE-2017-8943

    Last Modified: 20 Apr 2025

    The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 15 May 2017
    9.8
    Critical

    CVE-2017-6889

    Last Modified: 20 Apr 2025

    An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.

    Published: 15 May 2017
    9.8
    Critical

    CVE-2017-6890

    Last Modified: 20 Apr 2025

    A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.

    Published: 15 May 2017
    9.8
    Critical

    CVE-2017-0223

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0252.

    Published: 15 May 2017
    9.8
    Critical

    CVE-2017-0252

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling objects in memory. aka "Scripting Engine Memory Corruption Vulnerability". This vulnerability is unique from CVE-2017-0223.

    Published: 15 May 2017
    Unknown

    CVE-2014-0051

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 May 2017
    6.5
    Medium

    CVE-2017-5655

    Last Modified: 20 Apr 2025

    In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.

    Published: 15 May 2017
    6.3
    Medium

    CVE-2017-7489

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

    Published: 15 May 2017
    5.3
    Medium

    CVE-2017-7490

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.

    Published: 15 May 2017
    4.3
    Medium

    CVE-2017-7491

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the course overview block" configuration setting.

    Published: 15 May 2017
    3.3
    Low

    CVE-2017-8933

    Last Modified: 20 Apr 2025

    Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (menu unavailability).

    Published: 15 May 2017
    5.5
    Medium

    CVE-2017-8934

    Last Modified: 20 Apr 2025

    PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).

    Published: 15 May 2017
    10
    Critical

    CVE-2017-7213

    Last Modified: 20 Apr 2025

    Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified vectors.

    Published: 15 May 2017
    7.5
    High

    CVE-2017-9049

    Last Modified: 18 Dec 2025

    libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerability causes programs that use libxml2, such as PHP, to crash. This vulnerability exists because of an incomplete fix for libxml2 Bug 759398.

    Published: 15 May 2017