CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2017-0892

    Last Modified: 20 Apr 2025

    Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

    Published: 8 May 2017
    3.5
    Low

    CVE-2017-0895

    Last Modified: 20 Apr 2025

    Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

    Published: 8 May 2017
    5.4
    Medium

    CVE-2017-0893

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

    Published: 8 May 2017
    4.3
    Medium

    CVE-2017-0894

    Last Modified: 20 Apr 2025

    Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

    Published: 8 May 2017
    8.8
    High

    CVE-2016-8202

    Last Modified: 20 Apr 2025

    A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected versions, non-root users can gain root access with a combination of shell commands and parameters.

    Published: 8 May 2017
    7.8
    High

    CVE-2016-10369

    Last Modified: 20 Apr 2025

    unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

    Published: 8 May 2017
    7.5
    High

    CVE-2016-8209

    Last Modified: 20 Apr 2025

    Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

    Published: 8 May 2017
    7.8
    High

    CVE-2017-6953

    Last Modified: 20 Apr 2025

    Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted input to SmartDiag.exe or SymDiag.exe.

    Published: 8 May 2017
    7
    High

    CVE-2017-6051

    Last Modified: 20 Apr 2025

    An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to run a malicious DLL file within the search path resulting in execution of arbitrary code.

    Published: 8 May 2017
    6.5
    Medium

    CVE-2017-8848

    Last Modified: 20 Apr 2025

    Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.

    Published: 8 May 2017
    7.5
    High

    CVE-2017-8825

    Last Modified: 20 Apr 2025

    A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCore and MailCore 2. A crash can occur in low-level/imf/mailimf.c during a failed parse of a Cc header containing multiple e-mail addresses.

    Published: 8 May 2017
    7.8
    High

    CVE-2017-8844

    Last Modified: 20 Apr 2025

    The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-8845

    Last Modified: 20 Apr 2025

    The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted archive.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-8842

    Last Modified: 20 Apr 2025

    The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted archive.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-8843

    Last Modified: 20 Apr 2025

    The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-8847

    Last Modified: 20 Apr 2025

    The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-8846

    Last Modified: 20 Apr 2025

    The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted archive.

    Published: 8 May 2017
    6.1
    Medium

    CVE-2017-8833

    Last Modified: 20 Apr 2025

    Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."

    Published: 8 May 2017
    6.1
    Medium

    CVE-2017-8832

    Last Modified: 20 Apr 2025

    Allen Disk 1.6 has XSS in the id parameter to downfile.php.

    Published: 8 May 2017
    9.1
    Critical

    CVE-2017-8827

    Last Modified: 20 Apr 2025

    forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

    Published: 8 May 2017
    7.8
    High

    CVE-2017-8829

    Last Modified: 20 Apr 2025

    Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a review of a source package with a crafted YAML file.

    Published: 8 May 2017
    9.8
    Critical

    CVE-2017-7474

    Last Modified: 20 Apr 2025

    It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.

    Published: 8 May 2017
    4.1
    Medium

    CVE-2017-7497

    Last Modified: 21 Nov 2024

    The dialog for creating cloud volumes (cinder provider) in CloudForms does not filter cloud tenants by user. An attacker with the ability to create storage volumes could use this to create storage volumes for any other tenant.

    Published: 8 May 2017
    9.8
    Critical

    CVE-2017-9148

    Last Modified: 20 Apr 2025

    The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

    Published: 8 May 2017
    7.5
    High

    CVE-2017-3139

    Last Modified: 21 Nov 2024

    A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response.

    Published: 8 May 2017
    5.5
    Medium

    CVE-2017-9150

    Last Modified: 20 Apr 2025

    The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.

    Published: 8 May 2017
    Unknown

    CVE-2017-1000041

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7271. Reason: This candidate is a reservation duplicate of CVE-2017-7271. Notes: All CVE users should reference CVE-2017-7271 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000393

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10220. Reason: This candidate is a reservation duplicate of CVE-2016-10220. Notes: All CVE users should reference CVE-2016-10220 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2017-1000019

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-5938. Reason: This candidate is a reservation duplicate of CVE-2017-5938. Notes: All CVE users should reference CVE-2017-5938 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2017-1000040

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7853. Reason: This candidate is a reservation duplicate of CVE-2017-7853. Notes: All CVE users should reference CVE-2017-7853 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    7.5
    High

    CVE-2017-8804

    Last Modified: 20 Apr 2025

    The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a related issue to CVE-2017-8779. NOTE: [Information provided from upstream and references

    Published: 7 May 2017
    Unknown

    CVE-2017-8784

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7263. Reason: This candidate is a reservation duplicate of CVE-2017-7263. Notes: All CVE users should reference CVE-2017-7263 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000362

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9849. Reason: This candidate is a reservation duplicate of CVE-2016-9849. Notes: All CVE users should reference CVE-2016-9849 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000365

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9852, CVE-2016-9853, CVE-2016-9854, CVE-2016-9855. Reason: This candidate is a reservation duplicate of CVE-2016-9852, CVE-2016-9853, CVE-2016-9854, and CVE-2016-9855. Notes: All CVE users should reference CVE-2016-9852, CVE-2016-9853, CVE-2016-9854, and/or CVE-2016-9855 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000361

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9848. Reason: This candidate is a reservation duplicate of CVE-2016-9848. Notes: All CVE users should reference CVE-2016-9848 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000363

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9850. Reason: This candidate is a reservation duplicate of CVE-2016-9850. Notes: All CVE users should reference CVE-2016-9850 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000364

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9851. Reason: This candidate is a reservation duplicate of CVE-2016-9851. Notes: All CVE users should reference CVE-2016-9851 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000360

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9847. Reason: This candidate is a reservation duplicate of CVE-2016-9847. Notes: All CVE users should reference CVE-2016-9847 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000366

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9856, CVE-2016-9857. Reason: This candidate is a reservation duplicate of CVE-2016-9856 and CVE-2016-9857. Notes: All CVE users should reference CVE-2016-9856 and/or CVE-2016-9857 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000367

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9858, CVE-2016-9859, CVE-2016-9860. Reason: This candidate is a reservation duplicate of CVE-2016-9858, CVE-2016-9859, and CVE-2016-9860. Notes: All CVE users should reference CVE-2016-9858, CVE-2016-9859, and/or CVE-2016-9860 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000368

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9861. Reason: This candidate is a reservation duplicate of CVE-2016-9861. Notes: All CVE users should reference CVE-2016-9861 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000369

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9862. Reason: This candidate is a reservation duplicate of CVE-2016-9862. Notes: All CVE users should reference CVE-2016-9862 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000370

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9863. Reason: This candidate is a reservation duplicate of CVE-2016-9863. Notes: All CVE users should reference CVE-2016-9863 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000371

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9864. Reason: This candidate is a reservation duplicate of CVE-2016-9864. Notes: All CVE users should reference CVE-2016-9864 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000372

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9865. Reason: This candidate is a reservation duplicate of CVE-2016-9865. Notes: All CVE users should reference CVE-2016-9865 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    Unknown

    CVE-2016-1000373

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9866. Reason: This candidate is a reservation duplicate of CVE-2016-9866. Notes: All CVE users should reference CVE-2016-9866 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 May 2017
    4
    Medium

    CVE-2017-9117

    Last Modified: 20 Apr 2025

    In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mentioning bmp2tiff does not imply that the activation point is in the bmp2tiff.c file (which was removed before the 4.0.7 release).

    Published: 7 May 2017
    6.5
    Medium

    CVE-2017-9261

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 6 May 2017
    8.8
    High

    CVE-2017-7923

    Last Modified: 20 Apr 2025

    A Password in Configuration File issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The password in configuration file vulnerability could allow a malicious user to escalate privileges or assume the identity of another user and access sensitive information.

    Published: 6 May 2017
    9.8
    Critical

    CVE-2017-7909

    Last Modified: 20 Apr 2025

    A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.

    Published: 6 May 2017