CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-8114

    Last Modified: 20 Apr 2025

    Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before 1.2.5. The problem is caused by an improperly restricted exec call in the virtualmin and sasl drivers of the password plugin.

    Published: 29 Apr 2017
    8.8
    High

    CVE-2017-7981

    Last Modified: 20 Apr 2025

    Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an authenticated Tuleap user can control this value, even with shell metacharacters, as demonstrated by a '<?plugin SyntaxHighlighter syntax="c;id"' line to execute the id command.

    Published: 29 Apr 2017
    9.8
    Critical

    CVE-2017-6553

    Last Modified: 20 Apr 2025

    Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.

    Published: 29 Apr 2017
    8.8
    High

    CVE-2017-8361

    Last Modified: 20 Apr 2025

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

    Published: 29 Apr 2017
    6.5
    Medium

    CVE-2017-7644

    Last Modified: 20 Apr 2025

    The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-70541.

    Published: 29 Apr 2017
    6.5
    Medium

    CVE-2017-8362

    Last Modified: 20 Apr 2025

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.

    Published: 29 Apr 2017
    6.5
    Medium

    CVE-2017-8363

    Last Modified: 20 Apr 2025

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

    Published: 29 Apr 2017
    6.5
    Medium

    CVE-2017-8365

    Last Modified: 20 Apr 2025

    The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.

    Published: 29 Apr 2017
    5.5
    Medium

    CVE-2017-8908

    Last Modified: 20 Apr 2025

    The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PostScript document.

    Published: 29 Apr 2017
    5.9
    Medium

    CVE-2017-20004

    Last Modified: 21 Nov 2024

    In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be used across threads with any types, allowing for memory safety issues through race conditions.

    Published: 29 Apr 2017
    9.8
    Critical

    CVE-2017-7945

    Last Modified: 20 Apr 2025

    The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, 7.1.x before 7.1.9, and 8.x before 8.0.2 provides different error messages for failed login attempts depending on whether the username exists, which allows remote attackers to enumerate account names and conduct brute-force attacks via a series of requests, aka PAN-SA-2017-0014 and PAN-72769.

    Published: 29 Apr 2017
    8.8
    High

    CVE-2017-6250

    Last Modified: 20 Apr 2025

    NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.

    Published: 28 Apr 2017
    7.3
    High

    CVE-2016-8587

    Last Modified: 20 Apr 2025

    dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.

    Published: 28 Apr 2017
    9.8
    Critical

    CVE-2016-8584

    Last Modified: 20 Apr 2025

    Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8585

    Last Modified: 20 Apr 2025

    admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8586

    Last Modified: 20 Apr 2025

    detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8589

    Last Modified: 20 Apr 2025

    log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8590

    Last Modified: 20 Apr 2025

    log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8591

    Last Modified: 20 Apr 2025

    log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8592

    Last Modified: 20 Apr 2025

    log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2016-8593

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.

    Published: 28 Apr 2017
    7.3
    High

    CVE-2016-8588

    Last Modified: 20 Apr 2025

    The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-1141

    Last Modified: 20 Apr 2025

    IBM Insights Foundation for Energy 1.0, 1.5, and 1.6 could allow an authenticated user to obtain sensitive information from error messages. IBM X-Force ID: 121907.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-1194

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 123669.

    Published: 28 Apr 2017
    Unknown

    CVE-2017-1298

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-8106. Reason: This candidate is a reservation duplicate of CVE-2016-8106. Notes: All CVE users should reference CVE-2016-8106 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Apr 2017
    7.3
    High

    CVE-2017-2101

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecified vectors.

    Published: 28 Apr 2017
    5.9
    Medium

    CVE-2017-2103

    Last Modified: 20 Apr 2025

    The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Apr 2017
    7.8
    High

    CVE-2017-2107

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Self-extracting archive files created by 7-ZIP32.DLL 9.22.00.01 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Apr 2017
    5.9
    Medium

    CVE-2017-2110

    Last Modified: 20 Apr 2025

    The Access CX App for Android prior to 2.0.0.1 and for iOS prior to 2.0.2 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2140

    Last Modified: 20 Apr 2025

    Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.

    Published: 28 Apr 2017
    5.3
    Medium

    CVE-2017-2143

    Last Modified: 20 Apr 2025

    CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.

    Published: 28 Apr 2017
    5.4
    Medium

    CVE-2017-2148

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2016-7839

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Olive Blog allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 28 Apr 2017
    5.5
    Medium

    CVE-2016-7843

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-2090

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-2098

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2106

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting vulnerabilities in Webmin versions prior to 1.830 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-2115

    Last Modified: 20 Apr 2025

    Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2118

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    5.3
    Medium

    CVE-2017-2139

    Last Modified: 20 Apr 2025

    CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2147

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    7.8
    High

    CVE-2017-2154

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUST School 6 Premium, Hanako Police 5, JUST Police 3, Hanako 2017 trial version allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Apr 2017
    7.8
    High

    CVE-2017-2156

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.

    Published: 28 Apr 2017
    4.2
    Medium

    CVE-2016-7815

    Last Modified: 20 Apr 2025

    Remote Service Manager 3.0.0 to 3.1.4 fails to verify client certificates, which may allow remote attackers to gain access to systems on the network.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2016-7841

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Olive Diary DX allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 28 Apr 2017
    5.5
    Medium

    CVE-2016-7842

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2016-7840

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via the month parameter.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-2091

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages function to alter the status of phone messages via unspecified vectors.

    Published: 28 Apr 2017
    5.4
    Medium

    CVE-2017-2092

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-2093

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.

    Published: 28 Apr 2017