CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2017-2094

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-2095

    Last Modified: 20 Apr 2025

    Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.

    Published: 28 Apr 2017
    9.8
    Critical

    CVE-2017-2096

    Last Modified: 20 Apr 2025

    smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2097

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 28 Apr 2017
    6.3
    Medium

    CVE-2017-2100

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via unspecified vectors.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2102

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 28 Apr 2017
    5.9
    Medium

    CVE-2017-2104

    Last Modified: 20 Apr 2025

    The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Apr 2017
    5.9
    Medium

    CVE-2017-2105

    Last Modified: 20 Apr 2025

    The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Apr 2017
    7.8
    High

    CVE-2017-2108

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in PrimeDrive Desktop Application 1.4.3 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Apr 2017
    2.5
    Low

    CVE-2017-2109

    Last Modified: 20 Apr 2025

    Cybozu KUNAI for Android 3.0.4 to 3.0.5.1 allow remote attackers to obtain log information through a malicious Android application.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2112

    Last Modified: 20 Apr 2025

    TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    4.3
    Medium

    CVE-2017-2116

    Last Modified: 20 Apr 2025

    Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.

    Published: 28 Apr 2017
    4.9
    Medium

    CVE-2017-2117

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.

    Published: 28 Apr 2017
    8.6
    High

    CVE-2017-2119

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 28 Apr 2017
    7.2
    High

    CVE-2017-2120

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2124

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via contact.php.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2128

    Last Modified: 20 Apr 2025

    Security guide for website operators allows remote attackers to execute arbitrary OS commands via specially crafted saved data.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2134

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2135

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2136

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

    Published: 28 Apr 2017
    3.7
    Low

    CVE-2017-2137

    Last Modified: 20 Apr 2025

    ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.

    Published: 28 Apr 2017
    7.2
    High

    CVE-2017-2141

    Last Modified: 20 Apr 2025

    WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    9.8
    Critical

    CVE-2017-2142

    Last Modified: 20 Apr 2025

    Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    5.3
    Medium

    CVE-2017-2150

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2151

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    6.8
    Medium

    CVE-2017-2152

    Last Modified: 20 Apr 2025

    WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    6.3
    Medium

    CVE-2017-2099

    Last Modified: 20 Apr 2025

    Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote code execution via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2111

    Last Modified: 20 Apr 2025

    HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier may allow a remote attackers to display false information.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2113

    Last Modified: 20 Apr 2025

    Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 28 Apr 2017
    5.4
    Medium

    CVE-2017-2114

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    6.1
    Medium

    CVE-2017-2123

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2125

    Last Modified: 20 Apr 2025

    Privilege escalation vulnerability in CentreCOM AR260S V2 remote authenticated attackers to gain privileges via the guest account.

    Published: 28 Apr 2017
    5.4
    Medium

    CVE-2017-2127

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2017
    7.8
    High

    CVE-2017-2130

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer version Ver. 3.7.13 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2149

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in installers of the software for SDHC/SDXC Memory Card with embedded NFC functionality Software Update Tool V1.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Configuration Software V3.0.2 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WE series<W-03>) V3.00.01, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WD/WC series<W-02>) V2.00.03 and earlier, SDHC Memory Card with embedded wireless LAN functionality FlashAir Software Update tool (SD-WB/WL series) V1.00.04 and earlier, SDHC Memory Card with embedded TransferJet functionality Configuration Software V1.02 and earlier, SDHC Memory Card with embedded TransferJet functionality Software Update tool V1.00.06 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 28 Apr 2017
    7.5
    High

    CVE-2017-2153

    Last Modified: 20 Apr 2025

    SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause a denial of service via specially crafted IPv4 UDP packets.

    Published: 28 Apr 2017
    8.8
    High

    CVE-2017-2155

    Last Modified: 20 Apr 2025

    Buffer overflow in Hoozin Viewer 2, 3, 4.1.5.15 and earlier, 5.1.2.13 and earlier, and 6.0.3.09 and earlier allows remote attackers to execute arbitrary code via specially crafted webpage.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-9409

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 28 Apr 2017
    9.8
    Critical

    CVE-2017-7895

    Last Modified: 20 Apr 2025

    The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possibly have unspecified other impact via crafted requests, related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c.

    Published: 28 Apr 2017
    7.5
    High

    CVE-2017-8309

    Last Modified: 20 Apr 2025

    Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-9405

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadICONImage function in icon.c:452 allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-9407

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadPALMImage function in palm.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-8379

    Last Modified: 20 Apr 2025

    Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-9440

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPSDChannel in coders/psd.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 28 Apr 2017
    6.5
    Medium

    CVE-2017-9439

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, a memory leak was found in the function ReadPDBImage in coders/pdb.c, which allows attackers to cause a denial of service via a crafted file.

    Published: 28 Apr 2017
    9.8
    Critical

    CVE-2017-8305

    Last Modified: 20 Apr 2025

    The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2017-8308

    Last Modified: 20 Apr 2025

    In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of the Avast product. This bypasses the Self-Defense feature of the product, opening a door to subsequent attack on many of its components.

    Published: 27 Apr 2017
    9.8
    Critical

    CVE-2017-8307

    Last Modified: 20 Apr 2025

    In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible to launch predefined binaries, or replace or delete arbitrary files. This vulnerability is exploitable by any unprivileged user when Avast Self-Defense is disabled. It is also exploitable in conjunction with CVE-2017-8308 when Avast Self-Defense is enabled. The vulnerability allows for Denial of Service attacks and hiding traces of a possible attack.

    Published: 27 Apr 2017
    5.4
    Medium

    CVE-2017-8302

    Last Modified: 20 Apr 2025

    Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsiteflat.cfm, admin/core/views/cusers/inc/dsp_nextn.cfm, admin/core/views/cusers/inc/dsp_search_form.cfm, admin/core/views/cusers/inc/dsp_users_list.cfm, admin/core/views/cusers/list.cfm, and admin/core/views/cusers/listusers.cfm.

    Published: 27 Apr 2017
    5.3
    Medium

    CVE-2017-8301

    Last Modified: 20 Apr 2025

    LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.

    Published: 27 Apr 2017