CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-4442

    Last Modified: 20 Apr 2025

    The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.

    Published: 2 May 2017
    4.9
    Medium

    CVE-2016-5810

    Last Modified: 20 Apr 2025

    upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.

    Published: 2 May 2017
    5.9
    Medium

    CVE-2016-4467

    Last Modified: 20 Apr 2025

    The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when using the SChannel-based security layer, which allows man-in-the-middle attackers to spoof servers via an arbitrary valid certificate.

    Published: 2 May 2017
    9.8
    Critical

    CVE-2016-5006

    Last Modified: 20 Apr 2025

    The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.

    Published: 2 May 2017
    5.3
    Medium

    CVE-2016-5063

    Last Modified: 20 Apr 2025

    The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.

    Published: 2 May 2017
    9.8
    Critical

    CVE-2017-6551

    Last Modified: 20 Apr 2025

    Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.

    Published: 2 May 2017
    7.5
    High

    CVE-2017-7483

    Last Modified: 20 Apr 2025

    Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.

    Published: 2 May 2017
    3.3
    Low

    CVE-2017-8418

    Last Modified: 20 Apr 2025

    RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.

    Published: 2 May 2017
    9.8
    Critical

    CVE-2017-5689

    Last Modified: 22 Apr 2026

    An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

    Published: 2 May 2017
    7.5
    High

    CVE-2017-5068

    Last Modified: 20 Apr 2025

    Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page.

    Published: 2 May 2017
    7.8
    High

    CVE-2017-7487

    Last Modified: 20 Apr 2025

    The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a failed SIOCGIFADDR ioctl call for an IPX interface.

    Published: 2 May 2017
    8.8
    High

    CVE-2017-8904

    Last Modified: 20 Apr 2025

    Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) operations, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-214.

    Published: 2 May 2017
    7.8
    High

    CVE-2017-10662

    Last Modified: 20 Apr 2025

    The sanity_check_raw_super function in fs/f2fs/super.c in the Linux kernel before 4.11.1 does not validate the segment count, which allows local users to gain privileges via unspecified vectors.

    Published: 2 May 2017
    5.9
    Medium

    CVE-2017-6512

    Last Modified: 20 Apr 2025

    Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.

    Published: 2 May 2017
    8.8
    High

    CVE-2017-8903

    Last Modified: 20 Apr 2025

    Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-213.

    Published: 2 May 2017
    8.8
    High

    CVE-2017-8905

    Last Modified: 20 Apr 2025

    Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arbitrary code on the host OS, aka XSA-215.

    Published: 2 May 2017
    8.8
    High

    CVE-2017-8403

    Last Modified: 20 Apr 2025

    360fly 4K cameras allow unauthenticated Wi-Fi password changes and complete access with REST by using the Bluetooth Low Energy pairing procedure, which is available at any time and does not require a password. This affects firmware 2.1.4. Exploitation can use the 360fly Android or iOS application, or the BlueZ gatttool program.

    Published: 1 May 2017
    6.5
    Medium

    CVE-2017-6564

    Last Modified: 20 Apr 2025

    On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks.

    Published: 1 May 2017
    8.8
    High

    CVE-2017-8400

    Last Modified: 20 Apr 2025

    In SWFTools 0.9.2, an out-of-bounds write of heap data can occur in the function png_load() in lib/png.c:755. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS; it might cause arbitrary code execution.

    Published: 1 May 2017
    6.5
    Medium

    CVE-2017-8401

    Last Modified: 20 Apr 2025

    In SWFTools 0.9.2, an out-of-bounds read of heap data can occur in the function png_load() in lib/png.c:724. This issue can be triggered by a malformed PNG file that is mishandled by png2swf. Attackers could exploit this issue for DoS.

    Published: 1 May 2017
    8.8
    High

    CVE-2017-6565

    Last Modified: 20 Apr 2025

    On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload.

    Published: 1 May 2017
    5.4
    Medium

    CVE-2017-8376

    Last Modified: 20 Apr 2025

    GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.

    Published: 1 May 2017
    5.3
    Medium

    CVE-2017-8388

    Last Modified: 20 Apr 2025

    GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.

    Published: 1 May 2017
    8.8
    High

    CVE-2017-8377

    Last Modified: 20 Apr 2025

    GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.

    Published: 1 May 2017
    7.5
    High

    CVE-2017-6128

    Last Modified: 20 Apr 2025

    An attacker may be able to cause a denial-of-service (DoS) attack against the sshd component in F5 BIG-IP, Enterprise Manager, BIG-IQ, and iWorkflow.

    Published: 1 May 2017
    6.1
    Medium

    CVE-2017-5631

    Last Modified: 20 Apr 2025

    An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

    Published: 1 May 2017
    9.1
    Critical

    CVE-2016-8649

    Last Modified: 20 Apr 2025

    lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of syscalls.

    Published: 1 May 2017
    5.3
    Medium

    CVE-2017-8383

    Last Modified: 20 Apr 2025

    Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.

    Published: 1 May 2017
    6.1
    Medium

    CVE-2017-8384

    Last Modified: 20 Apr 2025

    Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.

    Published: 1 May 2017
    5.3
    Medium

    CVE-2017-8385

    Last Modified: 20 Apr 2025

    Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.

    Published: 1 May 2017
    5.5
    Medium

    CVE-2016-10351

    Last Modified: 20 Apr 2025

    Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.

    Published: 1 May 2017
    9.1
    Critical

    CVE-2017-6520

    Last Modified: 20 Apr 2025

    The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.

    Published: 1 May 2017
    5.5
    Medium

    CVE-2017-8374

    Last Modified: 20 Apr 2025

    The mad_bit_skip function in bit.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

    Published: 1 May 2017
    4.7
    Medium

    CVE-2017-8372

    Last Modified: 20 Apr 2025

    The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b, if NDEBUG is omitted, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted audio file.

    Published: 1 May 2017
    7.8
    High

    CVE-2017-8373

    Last Modified: 20 Apr 2025

    The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

    Published: 1 May 2017
    9.8
    Critical

    CVE-2017-8378

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via vectors related to m_offsets.size.

    Published: 1 May 2017
    4.7
    Medium

    CVE-2017-0627

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the kernel UVC driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33300353.

    Published: 1 May 2017
    4.7
    Medium

    CVE-2017-0630

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the kernel trace subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34277115.

    Published: 1 May 2017
    6.8
    Medium

    CVE-2017-8371

    Last Modified: 20 Apr 2025

    Schneider Electric StruxureWare Data Center Expert before 7.4.0 uses cleartext RAM storage for passwords, which might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 30 Apr 2017
    8.8
    High

    CVE-2017-8081

    Last Modified: 20 Apr 2025

    Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.

    Published: 30 Apr 2017
    7.8
    High

    CVE-2017-8364

    Last Modified: 20 Apr 2025

    The read_buf function in stream.c in rzip 2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted archive.

    Published: 30 Apr 2017
    9.8
    Critical

    CVE-2017-8366

    Last Modified: 20 Apr 2025

    The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted filter that is mishandled by etterfilter.

    Published: 30 Apr 2017
    7.8
    High

    CVE-2017-8367

    Last Modified: 20 Apr 2025

    Buffer overflow in Ether Software Easy MOV Converter 1.4.24, Easy DVD Creator, Easy MPEG/AVI/DIVX/WMV/RM to DVD, Easy Avi/Divx/Xvid to DVD Burner, Easy MPEG to DVD Burner, Easy WMV/ASF/ASX to DVD Burner, Easy RM RMVB to DVD Burner, Easy CD DVD Copy, MP3/AVI/MPEG/WMV/RM to Audio CD Burner, MP3/WAV/OGG/WMA/AC3 to CD Burner, MP3 WAV to CD Burner, My Video Converter, Easy AVI DivX Converter, Easy Video to iPod Converter, Easy Video to PSP Converter, Easy Video to 3GP Converter, Easy Video to MP4 Converter, and Easy Video to iPod/MP4/PSP/3GP Converter allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long username.

    Published: 30 Apr 2017
    7.8
    High

    CVE-2017-7721

    Last Modified: 20 Apr 2025

    IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.

    Published: 30 Apr 2017
    5.5
    Medium

    CVE-2017-8339

    Last Modified: 20 Apr 2025

    PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.

    Published: 30 Apr 2017
    9.8
    Critical

    CVE-2017-8359

    Last Modified: 20 Apr 2025

    Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.

    Published: 30 Apr 2017
    8.1
    High

    CVE-2017-8342

    Last Modified: 20 Apr 2025

    Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method.

    Published: 30 Apr 2017
    8.8
    High

    CVE-2017-8326

    Last Modified: 20 Apr 2025

    libimageworsener.a in ImageWorsener before 1.3.1 has "left shift cannot be represented in type int" undefined behavior issues, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image, related to imagew-bmp.c and imagew-util.c.

    Published: 29 Apr 2017
    6.5
    Medium

    CVE-2017-8327

    Last Modified: 20 Apr 2025

    The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted image.

    Published: 29 Apr 2017
    8.8
    High

    CVE-2017-8325

    Last Modified: 20 Apr 2025

    The iw_process_cols_to_intermediate function in imagew-main.c in libimageworsener.a in ImageWorsener before 1.3.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image.

    Published: 29 Apr 2017