CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2017-8298

    Last Modified: 20 Apr 2025

    cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.

    Published: 27 Apr 2017
    9.1
    Critical

    CVE-2017-5135

    Last Modified: 20 Apr 2025

    Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D3928SL-P15-13-A386-c3420r55105-160127a could be reached by any SNMP community string from the Internet; also, you can write in the MIB because it provides write properties, aka Stringbleed. NOTE: the string-bleed/StringBleed-CVE-2017-5135 GitHub repository is not a valid reference as of 2017-04-27; it contains Trojan horse code purported to exploit this vulnerability.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2017-8296

    Last Modified: 20 Apr 2025

    kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed in the password manager are written there. This can lead to the disclosure of the master password if the "password" command is used with an argument. The names of the password entries created and consulted are also accessible in cleartext.

    Published: 27 Apr 2017
    9.8
    Critical

    CVE-2017-8297

    Last Modified: 20 Apr 2025

    A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).

    Published: 27 Apr 2017
    9.8
    Critical

    CVE-2017-3066

    Last Modified: 22 Apr 2026

    Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

    Published: 27 Apr 2017
    6.1
    Medium

    CVE-2017-3008

    Last Modified: 20 Apr 2025

    Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2017-5186

    Last Modified: 20 Apr 2025

    Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch 9 Hotfix 2, and NetIQ eDirectory 9.x before 9.0.2 Hotfix 2 (9.0.2.2) use the deprecated MD5 hashing algorithm in a communications certificate.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2017-8294

    Last Modified: 20 Apr 2025

    libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2017-7415

    Last Modified: 20 Apr 2025

    Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the drafts diff REST resource.

    Published: 27 Apr 2017
    9.8
    Critical

    CVE-2017-8289

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.

    Published: 27 Apr 2017
    8.8
    High

    CVE-2017-6037

    Last Modified: 20 Apr 2025

    A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow when a maliciously crafted project file is run by the system.

    Published: 27 Apr 2017
    8.8
    High

    CVE-2017-6035

    Last Modified: 20 Apr 2025

    A Stack-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overflow, which could result in denial of service when a malicious project file is run on the system.

    Published: 27 Apr 2017
    7.5
    High

    CVE-2018-1000127

    Last Modified: 21 Nov 2024

    memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable via network connectivity to the memcached service. This vulnerability appears to have been fixed in 1.4.37 and later.

    Published: 27 Apr 2017
    3.3
    Low

    CVE-2017-1000242

    Last Modified: 20 Apr 2025

    Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure

    Published: 27 Apr 2017
    9.8
    Critical

    CVE-2017-7476

    Last Modified: 20 Apr 2025

    Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.

    Published: 27 Apr 2017
    5.5
    Medium

    CVE-2017-8421

    Last Modified: 20 Apr 2025

    The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this.

    Published: 27 Apr 2017
    7.3
    High

    CVE-2017-3162

    Last Modified: 20 Apr 2025

    HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query parameter that is not validated in Apache Hadoop before 2.7.0.

    Published: 26 Apr 2017
    6.1
    Medium

    CVE-2017-3161

    Last Modified: 20 Apr 2025

    The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.

    Published: 26 Apr 2017
    5.6
    Medium

    CVE-2016-8924

    Last Modified: 20 Apr 2025

    IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 118537.

    Published: 26 Apr 2017
    5.9
    Medium

    CVE-2016-8962

    Last Modified: 20 Apr 2025

    IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 118851.

    Published: 26 Apr 2017
    5.3
    Medium

    CVE-2017-1170

    Last Modified: 20 Apr 2025

    IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.

    Published: 26 Apr 2017
    7.5
    High

    CVE-2017-6054

    Last Modified: 6 Apr 2026

    A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information.

    Published: 26 Apr 2017
    3.7
    Low

    CVE-2017-6052

    Last Modified: 6 Apr 2026

    A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to access or influence communications between the identified endpoints.

    Published: 26 Apr 2017
    7
    High

    CVE-2017-8284

    Last Modified: 20 Apr 2025

    The disas_insn function in target/i386/translate.c in QEMU before 2.9.0, when TCG mode without hardware acceleration is used, does not limit the instruction size, which allows local users to gain privileges by creating a modified basic block that injects code into a setuid program, as demonstrated by procmail. NOTE: the vendor has stated "this bug does not violate any security guarantees QEMU makes.

    Published: 26 Apr 2017
    7.8
    High

    CVE-2017-7720

    Last Modified: 20 Apr 2025

    Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.

    Published: 26 Apr 2017
    7.8
    High

    CVE-2017-7293

    Last Modified: 20 Apr 2025

    The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50.

    Published: 26 Apr 2017
    9.8
    Critical

    CVE-2017-8283

    Last Modified: 20 Apr 2025

    dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8356

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8355

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadMTVImage function in mtv.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8351

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadPCDImage function in pcd.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8343

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadAAIImage function in aai.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    8.8
    High

    CVE-2017-1000354

    Last Modified: 21 Nov 2024

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to a login command which allowed impersonating any Jenkins user. The `login` command available in the remoting-based CLI stored the encrypted user name of the successfully authenticated user in a cache file used to authenticate further commands. Users with sufficient permission to create secrets in Jenkins, and download their encrypted values (e.g. with Job/Configure permission), were able to impersonate any other Jenkins user on the same instance.

    Published: 26 Apr 2017
    9.8
    Critical

    CVE-2017-1000232

    Last Modified: 20 Apr 2025

    A double-free vulnerability in str2host.c in ldns 1.7.0 have unspecified impact and attack vectors.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-1000355

    Last Modified: 21 Nov 2024

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an XStream: Java crash when trying to instantiate void/Void.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8345

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadMNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8347

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadEXRImage function in exr.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8350

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadJNGImage function in png.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8354

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadBMPImage function in bmp.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    5.5
    Medium

    CVE-2017-9059

    Last Modified: 20 Apr 2025

    The NFSv4 implementation in the Linux kernel through 4.11.1 allows local users to cause a denial of service (resource consumption) by leveraging improper channel callback shutdown when unmounting an NFSv4 filesystem, aka a "module reference and kernel daemon" leak.

    Published: 26 Apr 2017
    8.8
    High

    CVE-2017-1000356

    Last Modified: 21 Nov 2024

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an issue in the Jenkins user database authentication realm: create an account if signup is enabled; or create an account if the victim is an administrator, possibly deleting the existing default admin user in the process and allowing a wide variety of impacts.

    Published: 26 Apr 2017
    7.1
    High

    CVE-2017-11472

    Last Modified: 20 Apr 2025

    The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8344

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadPCXImage function in pcx.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8346

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadDCMImage function in dcm.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8348

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadMATImage function in mat.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8349

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadSFWImage function in sfw.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8352

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadXWDImage function in xwd.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8353

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadPICTImage function in pict.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    6.5
    Medium

    CVE-2017-8357

    Last Modified: 20 Apr 2025

    In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.

    Published: 26 Apr 2017
    9.8
    Critical

    CVE-2017-1000353

    Last Modified: 5 Nov 2025

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

    Published: 26 Apr 2017
    7.8
    High

    CVE-2017-8291

    Last Modified: 21 Apr 2026

    Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in April 2017.

    Published: 26 Apr 2017