CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-6865

    Last Modified: 20 Apr 2025

    A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 (TIA Portal) V14 (All versions < V14 SP1), SIMATIC STEP 7 V5.X (All versions < V5.6), SIMATIC WinAC RTX 2010 SP2 (All versions), SIMATIC WinAC RTX F 2010 SP2 (All versions), SIMATIC WinCC (TIA Portal) V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) V14 (All versions < V14 SP1), SIMATIC WinCC V7.2 and prior (All versions), SIMATIC WinCC V7.3 (All versions < V7.3 Update 15), SIMATIC WinCC V7.4 (All versions < V7.4 SP1 Upd1), SIMATIC WinCC flexible 2008 (All versions < flexible 2008 SP5), SINAUT ST7CC (All versions installed in conjunction with SIMATIC WinCC < V7.3 Update 15), SINEMA Server (All versions < V14), SINUMERIK 808D Programming Tool (All versions < V4.7 SP4 HF2), SMART PC Access (All versions < V2.3), STEP 7 - Micro/WIN SMART (All versions < V2.3), Security Configuration Tool (SCT) (All versions < V5.0). Specially crafted PROFINET DCP broadcast packets sent to the affected products on a local Ethernet segment (Layer 2) could cause a Denial-of-Service condition of some services. The services require manual restart to recover.

    Published: 11 May 2017
    9.8
    Critical

    CVE-2017-8798

    Last Modified: 20 Apr 2025

    Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

    Published: 11 May 2017
    7.1
    High

    CVE-2017-2680

    Last Modified: 20 Apr 2025

    Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.

    Published: 11 May 2017
    7.5
    High

    CVE-2017-7486

    Last Modified: 20 Apr 2025

    PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.

    Published: 11 May 2017
    5.5
    Medium

    CVE-2017-18360

    Last Modified: 21 Nov 2024

    In change_port_settings in drivers/usb/serial/io_ti.c in the Linux kernel before 4.11.3, local users could cause a denial of service by division-by-zero in the serial device layer by trying to set very high baud rates.

    Published: 11 May 2017
    9
    Critical

    CVE-2017-2292

    Last Modified: 20 Apr 2025

    Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.

    Published: 11 May 2017
    9.8
    Critical

    CVE-2017-6886

    Last Modified: 20 Apr 2025

    An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.

    Published: 11 May 2017
    7.8
    High

    CVE-2017-6887

    Last Modified: 20 Apr 2025

    A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs.

    Published: 11 May 2017
    8.7
    High

    CVE-2017-7464

    Last Modified: 21 Nov 2024

    It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use this flaw to cause DoS, SSRF, or information disclosure if they are able to provide XML content for parsing.

    Published: 11 May 2017
    5.9
    Medium

    CVE-2017-7485

    Last Modified: 20 Apr 2025

    In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that the PGREQUIRESSL environment variable was no longer enforcing a SSL/TLS connection to a PostgreSQL server. An active Man-in-the-Middle attacker could use this flaw to strip the SSL/TLS protection from a connection between a client and a server.

    Published: 11 May 2017
    8.2
    High

    CVE-2017-2295

    Last Modified: 20 Apr 2025

    Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code execution. This change constrains the format of data on the wire to PSON or safely decoded YAML.

    Published: 11 May 2017
    5.5
    Medium

    CVE-2017-6888

    Last Modified: 21 Nov 2024

    An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.

    Published: 11 May 2017
    7.5
    High

    CVE-2017-7484

    Last Modified: 20 Apr 2025

    It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information. An unprivileged attacker could use this flaw to steal some information from tables they are otherwise not allowed to access.

    Published: 11 May 2017
    3.5
    Low

    CVE-2017-7509

    Last Modified: 21 Nov 2024

    An input validation error was found in Red Hat Certificate System's handling of client provided certificates before 8.1.20-1. If the certreq field is not present in a certificate an assertion error is triggered causing a denial of service.

    Published: 11 May 2017
    9.8
    Critical

    CVE-2017-8895

    Last Modified: 20 Apr 2025

    In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.

    Published: 10 May 2017
    6.1
    Medium

    CVE-2017-8892

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web script or HTML persistently via the name of an uploaded image.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-8852

    Last Modified: 20 Apr 2025

    SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file. The vendor response is SAP Security Note 2441560.

    Published: 10 May 2017
    6.1
    Medium

    CVE-2017-3894

    Last Modified: 20 Apr 2025

    A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.6.1 and earlier, and all versions of BES12, allows attackers to execute actions in the context of a Management Console administrator by uploading a malicious script and then persuading a target administrator to view the specific location of the malicious script within the Management Console.

    Published: 10 May 2017
    5.5
    Medium

    CVE-2017-8891

    Last Modified: 20 Apr 2025

    Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.

    Published: 10 May 2017
    Unknown

    CVE-2017-6959

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 May 2017
    8.8
    High

    CVE-2017-4895

    Last Modified: 20 Apr 2025

    Airwatch Agent for Android contains a vulnerability that may allow a device to bypass root detection. Successful exploitation of this issue may result in an enrolled device having unrestricted access over local Airwatch security controls and data.

    Published: 10 May 2017
    3.8
    Low

    CVE-2017-4896

    Last Modified: 20 Apr 2025

    Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.

    Published: 10 May 2017
    5.4
    Medium

    CVE-2016-3032

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114516.

    Published: 10 May 2017
    5.4
    Medium

    CVE-2016-5888

    Last Modified: 20 Apr 2025

    IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 115084.

    Published: 10 May 2017
    8.8
    High

    CVE-2016-5889

    Last Modified: 20 Apr 2025

    IBM Interact 8.6, 9.0, 9.1, and 10.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 115085.

    Published: 10 May 2017
    5.4
    Medium

    CVE-2016-6035

    Last Modified: 20 Apr 2025

    IBM Rational Quality Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116896.

    Published: 10 May 2017
    4.8
    Medium

    CVE-2016-6037

    Last Modified: 20 Apr 2025

    IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 116918.

    Published: 10 May 2017
    8.1
    High

    CVE-2017-1103

    Last Modified: 20 Apr 2025

    IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 120665.

    Published: 10 May 2017
    8.1
    High

    CVE-2017-1137

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server 8.0 and 8.5.5 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to the admin console. IBM X-Force ID: 121549.

    Published: 10 May 2017
    9.8
    Critical

    CVE-2017-7886

    Last Modified: 20 Apr 2025

    Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.

    Published: 10 May 2017
    6.1
    Medium

    CVE-2017-7887

    Last Modified: 20 Apr 2025

    Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

    Published: 10 May 2017
    9.8
    Critical

    CVE-2017-7888

    Last Modified: 20 Apr 2025

    Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.

    Published: 10 May 2017
    6.8
    Medium

    CVE-2017-8879

    Last Modified: 20 Apr 2025

    Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

    Published: 10 May 2017
    7.5
    High

    CVE-2016-9250

    Last Modified: 20 Apr 2025

    In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-7698

    Last Modified: 20 Apr 2025

    A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via a malformed PDF document, possibly a consequence of an error in Gfx.cc in Xpdf 3.02.

    Published: 10 May 2017
    8.8
    High

    CVE-2017-5891

    Last Modified: 20 Apr 2025

    ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 have Login Page CSRF and Save Settings CSRF.

    Published: 10 May 2017
    6.5
    Medium

    CVE-2017-8877

    Last Modified: 20 Apr 2025

    ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.

    Published: 10 May 2017
    7.5
    High

    CVE-2017-5892

    Last Modified: 20 Apr 2025

    ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.

    Published: 10 May 2017
    6.1
    Medium

    CVE-2017-8876

    Last Modified: 20 Apr 2025

    Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.

    Published: 10 May 2017
    8.8
    High

    CVE-2017-8874

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Mautic 1.4.1 allow remote attackers to hijack the authentication of users for requests that (1) delete email campaigns or (2) delete contacts.

    Published: 10 May 2017
    6.5
    Medium

    CVE-2017-8875

    Last Modified: 20 Apr 2025

    CSRF in the Clean Login plugin before 1.8 for WordPress allows remote attackers to change the login redirect URL or logout redirect URL.

    Published: 10 May 2017
    7.5
    High

    CVE-2017-8868

    Last Modified: 20 Apr 2025

    acp/core/files.browser.php in flatCore 1.4.7 allows file deletion via directory traversal in the delete parameter to acp/acp.php. The risk might be limited to requests submitted through CSRF.

    Published: 10 May 2017
    6.5
    Medium

    CVE-2017-8878

    Last Modified: 20 Apr 2025

    ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow remote authenticated users to discover the Wi-Fi password via WPS_info.xml.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-8422

    Last Modified: 20 Apr 2025

    KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-9077

    Last Modified: 20 Apr 2025

    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-9076

    Last Modified: 20 Apr 2025

    The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE-2017-8890.

    Published: 10 May 2017
    5.5
    Medium

    CVE-2017-9503

    Last Modified: 20 Apr 2025

    QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas command processing.

    Published: 10 May 2017
    7.8
    High

    CVE-2017-0341

    Last Modified: 20 Apr 2025

    All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.

    Published: 9 May 2017
    7.8
    High

    CVE-2017-0342

    Last Modified: 20 Apr 2025

    All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.

    Published: 9 May 2017
    7
    High

    CVE-2017-0343

    Last Modified: 20 Apr 2025

    All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.

    Published: 9 May 2017