CVE Feed

    Dashboard / CVE

    8.3
    High

    CVE-2017-3512

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 7u131 and 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

    Published: 18 Apr 2017
    3.1
    Low

    CVE-2017-3539

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).

    Published: 18 Apr 2017
    7.3
    High

    CVE-2017-5661

    Last Modified: 20 Apr 2025

    In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.

    Published: 18 Apr 2017
    9
    Critical

    CVE-2017-7471

    Last Modified: 21 Nov 2024

    Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host directory. A privileged user inside guest could use this flaw to access host file system beyond the shared folder and potentially escalating their privileges on a host.

    Published: 18 Apr 2017
    7.7
    High

    CVE-2017-3511

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE). Supported versions that are affected are Java SE: 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

    Published: 18 Apr 2017
    8.3
    High

    CVE-2017-3514

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

    Published: 18 Apr 2017
    9.8
    Critical

    CVE-2017-8358

    Last Modified: 20 Apr 2025

    LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.

    Published: 18 Apr 2017
    8.8
    High

    CVE-2017-9462

    Last Modified: 20 Apr 2025

    In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.

    Published: 18 Apr 2017
    5.9
    Medium

    CVE-2017-3526

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded, JRockit. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

    Published: 18 Apr 2017
    3.7
    Low

    CVE-2017-3544

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

    Published: 18 Apr 2017
    7
    High

    CVE-2017-7467

    Last Modified: 21 Nov 2024

    A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious terminal device could potentially use this flaw to crash minicom, or execute arbitrary code in the context of the minicom process.

    Published: 18 Apr 2017
    7.8
    High

    CVE-2017-7948

    Last Modified: 20 Apr 2025

    Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via a crafted PostScript document.

    Published: 18 Apr 2017
    5.5
    Medium

    CVE-2017-7982

    Last Modified: 20 Apr 2025

    Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.

    Published: 18 Apr 2017
    5.4
    Medium

    CVE-2016-0228

    Last Modified: 20 Apr 2025

    IBM Marketing Platform 10.0 could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability in various scripts. An attacker could exploit this vulnerability to redirect a victim to arbitrary Web sites. IBM X-Force ID: 110236.

    Published: 17 Apr 2017
    5.7
    Medium

    CVE-2016-3037

    Last Modified: 20 Apr 2025

    IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.

    Published: 17 Apr 2017
    7.5
    High

    CVE-2016-3036

    Last Modified: 20 Apr 2025

    IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 114612.

    Published: 17 Apr 2017
    5.4
    Medium

    CVE-2017-1160

    Last Modified: 20 Apr 2025

    IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 122892.

    Published: 17 Apr 2017
    7.3
    High

    CVE-2017-1161

    Last Modified: 20 Apr 2025

    IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitrary commands on the system with the privileges of the www-data user. IBM X-Force ID: 122956.

    Published: 17 Apr 2017
    7.5
    High

    CVE-2017-7892

    Last Modified: 20 Apr 2025

    Sandstorm Cap'n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap'n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message.

    Published: 17 Apr 2017
    5.4
    Medium

    CVE-2016-3038

    Last Modified: 20 Apr 2025

    IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 114614.

    Published: 17 Apr 2017
    7.5
    High

    CVE-2017-5659

    Last Modified: 20 Apr 2025

    Apache Traffic Server before 6.2.1 generates a coredump when there is a mismatch between content length and chunked encoding.

    Published: 17 Apr 2017
    7.5
    High

    CVE-2016-5396

    Last Modified: 20 Apr 2025

    Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.

    Published: 17 Apr 2017
    6.1
    Medium

    CVE-2015-8256

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.

    Published: 17 Apr 2017
    9.8
    Critical

    CVE-2016-6726

    Last Modified: 20 Apr 2025

    Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.

    Published: 17 Apr 2017
    9.8
    Critical

    CVE-2016-6727

    Last Modified: 20 Apr 2025

    The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.

    Published: 17 Apr 2017
    7.5
    High

    CVE-2016-7551

    Last Modified: 20 Apr 2025

    chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

    Published: 17 Apr 2017
    4.3
    Medium

    CVE-2016-4868

    Last Modified: 20 Apr 2025

    Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.

    Published: 17 Apr 2017
    4.8
    Medium

    CVE-2016-4866

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Project function.

    Published: 17 Apr 2017
    4.3
    Medium

    CVE-2016-4867

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.

    Published: 17 Apr 2017
    4.8
    Medium

    CVE-2016-4865

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows attackers with administrator rights to inject arbitrary web script or HTML via the Customapp function.

    Published: 17 Apr 2017
    5.4
    Medium

    CVE-2016-4870

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.

    Published: 17 Apr 2017
    6.5
    Medium

    CVE-2016-4871

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.

    Published: 17 Apr 2017
    4.3
    Medium

    CVE-2016-4872

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.

    Published: 17 Apr 2017
    4.3
    Medium

    CVE-2016-4873

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.

    Published: 17 Apr 2017
    3.5
    Low

    CVE-2016-4874

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.

    Published: 17 Apr 2017
    6.5
    Medium

    CVE-2016-4869

    Last Modified: 20 Apr 2025

    Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.

    Published: 17 Apr 2017
    6.1
    Medium

    CVE-2017-7891

    Last Modified: 20 Apr 2025

    sourcebans-pp (SourceBans++) 1.5.4.7 has XSS in admin.comms.php via the rebanid parameter.

    Published: 17 Apr 2017
    9.8
    Critical

    CVE-2017-7375

    Last Modified: 3 Dec 2025

    A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).

    Published: 17 Apr 2017
    7.8
    High

    CVE-2017-0663

    Last Modified: 20 Apr 2025

    A remote code execution vulnerability in libxml2 could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37104170.

    Published: 17 Apr 2017
    9.8
    Critical

    CVE-2017-7376

    Last Modified: 21 Nov 2024

    Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

    Published: 17 Apr 2017
    6.5
    Medium

    CVE-2017-7941

    Last Modified: 20 Apr 2025

    The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

    Published: 17 Apr 2017
    6.5
    Medium

    CVE-2017-7942

    Last Modified: 20 Apr 2025

    The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

    Published: 17 Apr 2017
    6.5
    Medium

    CVE-2017-7943

    Last Modified: 20 Apr 2025

    The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

    Published: 17 Apr 2017
    8.8
    High

    CVE-2017-7615

    Last Modified: 20 Apr 2025

    MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.

    Published: 16 Apr 2017
    7.8
    High

    CVE-2017-7961

    Last Modified: 20 Apr 2025

    The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file. NOTE: third-party analysis reports "This is not a security issue in my view. The conversion surely is truncating the double into a long value, but there is no impact as the value is one of the RGB components.

    Published: 16 Apr 2017
    5.5
    Medium

    CVE-2017-7960

    Last Modified: 20 Apr 2025

    The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.

    Published: 16 Apr 2017
    8.8
    High

    CVE-2017-7881

    Last Modified: 20 Apr 2025

    BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.

    Published: 15 Apr 2017
    Unknown

    CVE-2017-7874

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 15 Apr 2017
    7.5
    High

    CVE-2017-16030

    Last Modified: 21 Nov 2024

    Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.

    Published: 15 Apr 2017
    6.1
    Medium

    CVE-2016-4875

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Apr 2017