CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2017-7694

    Last Modified: 20 Apr 2025

    Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-7689

    Last Modified: 20 Apr 2025

    A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-7691

    Last Modified: 20 Apr 2025

    A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.

    Published: 11 Apr 2017
    Unknown

    CVE-2016-2553

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Apr 2017
    Unknown

    CVE-2017-7469

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7466. Reason: This candidate is a reservation duplicate of CVE-2017-7466. Notes: All CVE users should reference CVE-2017-7466 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2013-6647

    Last Modified: 20 Apr 2025

    A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.

    Published: 11 Apr 2017
    8.8
    High

    CVE-2015-7893

    Last Modified: 20 Apr 2025

    SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.

    Published: 11 Apr 2017
    7.2
    High

    CVE-2017-6088

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.

    Published: 11 Apr 2017
    Unknown

    CVE-2017-5338

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Apr 2017
    Unknown

    CVE-2017-5339

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2016-0779

    Last Modified: 20 Apr 2025

    The EjbObjectInputStream class in Apache TomEE before 1.7.4 and 7.x before 7.0.0-M3 allows remote attackers to execute arbitrary code via a crafted serialized object.

    Published: 11 Apr 2017
    8.8
    High

    CVE-2016-4468

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 11 Apr 2017
    6.7
    Medium

    CVE-2017-5873

    Last Modified: 20 Apr 2025

    Unquoted Windows search path vulnerability in the guest service in Unisys s-Par before 4.4.20 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

    Published: 11 Apr 2017
    4.9
    Medium

    CVE-2017-7461

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not do any URI/path sanitization.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-7462

    Last Modified: 20 Apr 2025

    Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

    Published: 11 Apr 2017
    6.5
    Medium

    CVE-2017-5672

    Last Modified: 20 Apr 2025

    Kony Enterprise Mobile Management (EMM) before 4.2.5.2 has the vulnerability of disclosing the private key in clear-text when changing the parameters of the request.

    Published: 11 Apr 2017
    5.3
    Medium

    CVE-2016-7467

    Last Modified: 20 Apr 2025

    The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Service Provider (SP) connector, might allow traffic to be disrupted or failover initiated when a malformed, signed SAML authentication request from an authenticated user is sent via the SP connector.

    Published: 11 Apr 2017
    5.9
    Medium

    CVE-2016-10259

    Last Modified: 20 Apr 2025

    Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL server.

    Published: 11 Apr 2017
    8.8
    High

    CVE-2016-6811

    Last Modified: 20 Apr 2025

    In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

    Published: 11 Apr 2017
    6.1
    Medium

    CVE-2017-7621

    Last Modified: 20 Apr 2025

    Cross Site Scripting Vulnerability in core-eMLi in AuroMeera Technometrix Pvt. Ltd. eMLi V1.0 allows an Attacker to send malicious code, generally in the form of a browser-side script, to a different end user via the page parameter to code/student_portal/home.php. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.

    Published: 11 Apr 2017
    7.5
    High

    CVE-2017-16014

    Last Modified: 21 Nov 2024

    Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-3060

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScript2 code parser. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    5.5
    Medium

    CVE-2017-7697

    Last Modified: 20 Apr 2025

    In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.

    Published: 11 Apr 2017
    4.8
    Medium

    CVE-2017-2665

    Last Modified: 21 Nov 2024

    The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. Any local user who has access to system running skyring service will be able to get password in plain text.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-3059

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal script object. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-3062

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 when creating a getter/setter property. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-3063

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2 NetStream class. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    7.8
    High

    CVE-2017-3064

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    9
    Critical

    CVE-2017-7465

    Last Modified: 21 Nov 2024

    It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content for parsing. Doing a transform in JAXP requires the use of a 'javax.xml.transform.TransformerFactory'. If the FEATURE_SECURE_PROCESSING feature is set to 'true', it mitigates this vulnerability.

    Published: 11 Apr 2017
    5.5
    Medium

    CVE-2017-7742

    Last Modified: 20 Apr 2025

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-7856

    Last Modified: 20 Apr 2025

    LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.

    Published: 11 Apr 2017
    7.8
    High

    CVE-2017-3058

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    9.8
    Critical

    CVE-2017-3061

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Apr 2017
    4.7
    Medium

    CVE-2017-7473

    Last Modified: 13 Feb 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA based off of CNT 3. Further investigation determined that there was a secure method for using the directive. Notes: none.

    Published: 11 Apr 2017
    8
    High

    CVE-2017-7466

    Last Modified: 21 Nov 2024

    Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

    Published: 11 Apr 2017
    5.5
    Medium

    CVE-2017-7741

    Last Modified: 20 Apr 2025

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

    Published: 11 Apr 2017
    7.8
    High

    CVE-2016-8235

    Last Modified: 20 Apr 2025

    Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.

    Published: 10 Apr 2017
    8.1
    High

    CVE-2016-8237

    Last Modified: 20 Apr 2025

    Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2017-7647

    Last Modified: 20 Apr 2025

    SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.

    Published: 10 Apr 2017
    8.1
    High

    CVE-2017-7648

    Last Modified: 20 Apr 2025

    Foscam networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 10 Apr 2017
    6.5
    Medium

    CVE-2017-7646

    Last Modified: 20 Apr 2025

    SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.

    Published: 10 Apr 2017
    7.8
    High

    CVE-2016-10323

    Last Modified: 20 Apr 2025

    Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2016-10322

    Last Modified: 20 Apr 2025

    Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.

    Published: 10 Apr 2017
    8.8
    High

    CVE-2017-7622

    Last Modified: 20 Apr 2025

    dde-daemon, the daemon process of DDE (Deepin Desktop Environment) 15.0 through 15.3, runs with root privileges and hardly does anything to identify the user who calls the function through D-Bus. Anybody can change the grub config, even to append some arguments to make a backdoor or privilege escalation, by calling DoWriteGrubSettings() provided by dde-daemon.

    Published: 10 Apr 2017
    5.5
    Medium

    CVE-2017-7623

    Last Modified: 20 Apr 2025

    The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

    Published: 10 Apr 2017
    5.5
    Medium

    CVE-2017-7624

    Last Modified: 20 Apr 2025

    The iw_read_bmp_file function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to consume an amount of available memory via a crafted file.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2017-7625

    Last Modified: 20 Apr 2025

    In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.

    Published: 10 Apr 2017
    7.5
    High

    CVE-2015-7825

    Last Modified: 20 Apr 2025

    botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a certificate with a loop in the certificate chain.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2016-10311

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to the SAPSTARTSRV port, aka SAP Security Note 2295238.

    Published: 10 Apr 2017
    9.8
    Critical

    CVE-2015-7826

    Last Modified: 20 Apr 2025

    botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.foo.example.com.

    Published: 10 Apr 2017