CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-9219

    Last Modified: 20 Apr 2025

    A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to cause an unexpected reload of the device. The vulnerability is due to incomplete IPv6 UDP header validation. An attacker could exploit this vulnerability by sending a crafted IPv6 UDP packet to a specific port on the targeted device. An exploit could allow the attacker to impact the availability of the device as it could unexpectedly reload. This vulnerability affects Cisco Wireless LAN Controller (WLC) running software version 8.2.121.0 or 8.3.102.0. Cisco Bug IDs: CSCva98592.

    Published: 6 Apr 2017
    8.8
    High

    CVE-2017-6884

    Last Modified: 21 Apr 2026

    A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute arbitrary commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

    Published: 6 Apr 2017
    8.6
    High

    CVE-2017-7569

    Last Modified: 20 Apr 2025

    In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.

    Published: 6 Apr 2017
    8
    High

    CVE-2017-7571

    Last Modified: 20 Apr 2025

    public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.

    Published: 6 Apr 2017
    7.7
    High

    CVE-2017-7566

    Last Modified: 20 Apr 2025

    MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.

    Published: 6 Apr 2017
    5.9
    Medium

    CVE-2016-10319

    Last Modified: 20 Apr 2025

    In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code.

    Published: 6 Apr 2017
    8.8
    High

    CVE-2017-7565

    Last Modified: 20 Apr 2025

    Splunk Hadoop Connect App has a path traversal vulnerability that allows remote authenticated users to execute arbitrary code, aka ERP-2041.

    Published: 6 Apr 2017
    7.8
    High

    CVE-2017-2675

    Last Modified: 20 Apr 2025

    Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. The vulnerability is related to the installation of the configuration file "at.obdev.littlesnitchd.plist" which gets installed to /Library/LaunchDaemons.

    Published: 6 Apr 2017
    9.8
    Critical

    CVE-2017-7237

    Last Modified: 20 Apr 2025

    The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.

    Published: 6 Apr 2017
    9.8
    Critical

    CVE-2017-0305

    Last Modified: 20 Apr 2025

    F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when deployed using the Explicit Proxy feature plus SNAT Auto Map option for egress traffic.

    Published: 6 Apr 2017
    7.5
    High

    CVE-2017-5887

    Last Modified: 20 Apr 2025

    WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).

    Published: 6 Apr 2017
    8.8
    High

    CVE-2017-6968

    Last Modified: 20 Apr 2025

    GMV Checker ATM Security prior to 5.0.18 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka PT-2017-03.

    Published: 6 Apr 2017
    7.5
    High

    CVE-2017-7192

    Last Modified: 20 Apr 2025

    WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).

    Published: 6 Apr 2017
    7.4
    High

    CVE-2017-6130

    Last Modified: 20 Apr 2025

    F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic.

    Published: 6 Apr 2017
    7.5
    High

    CVE-2017-10810

    Last Modified: 20 Apr 2025

    Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

    Published: 6 Apr 2017
    5.5
    Medium

    CVE-2017-7452

    Last Modified: 20 Apr 2025

    The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 6 Apr 2017
    5.5
    Medium

    CVE-2017-7453

    Last Modified: 20 Apr 2025

    The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 6 Apr 2017
    5.5
    Medium

    CVE-2017-7454

    Last Modified: 20 Apr 2025

    The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

    Published: 6 Apr 2017
    5.5
    Medium

    CVE-2017-7448

    Last Modified: 20 Apr 2025

    The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.

    Published: 5 Apr 2017
    9.8
    Critical

    CVE-2017-7450

    Last Modified: 20 Apr 2025

    AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software update at an arbitrary time.

    Published: 5 Apr 2017
    8.8
    High

    CVE-2017-7447

    Last Modified: 20 Apr 2025

    HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

    Published: 5 Apr 2017
    8.8
    High

    CVE-2017-7446

    Last Modified: 20 Apr 2025

    HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.

    Published: 5 Apr 2017
    6.4
    Medium

    CVE-2017-0883

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

    Published: 5 Apr 2017
    4.3
    Medium

    CVE-2017-0885

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.

    Published: 5 Apr 2017
    4.3
    Medium

    CVE-2017-0884

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.

    Published: 5 Apr 2017
    6.5
    Medium

    CVE-2017-0886

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

    Published: 5 Apr 2017
    4.3
    Medium

    CVE-2017-0887

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

    Published: 5 Apr 2017
    4.3
    Medium

    CVE-2017-0888

    Last Modified: 20 Apr 2025

    Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navigation bar displayed in the files list contained partially user-controllable input leading to a potential misrepresentation of information.

    Published: 5 Apr 2017
    6.1
    Medium

    CVE-2017-7443

    Last Modified: 20 Apr 2025

    apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, related to lack of blocking for the %0[ad] regular expression.

    Published: 5 Apr 2017
    7.8
    High

    CVE-2017-7444

    Last Modified: 20 Apr 2025

    In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker has write access to the directory from which the product is executed.

    Published: 5 Apr 2017
    5.4
    Medium

    CVE-2016-3015

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

    Published: 5 Apr 2017
    8.8
    High

    CVE-2016-6100

    Last Modified: 20 Apr 2025

    IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000771.

    Published: 5 Apr 2017
    5.4
    Medium

    CVE-2016-3031

    Last Modified: 20 Apr 2025

    IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998887.

    Published: 5 Apr 2017
    5.3
    Medium

    CVE-2017-1180

    Last Modified: 20 Apr 2025

    The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.

    Published: 5 Apr 2017
    6.5
    Medium

    CVE-2017-6338

    Last Modified: 20 Apr 2025

    Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.

    Published: 5 Apr 2017
    6.5
    Medium

    CVE-2017-6339

    Last Modified: 20 Apr 2025

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure passage for HTTPS connections. It also allows administrators to upload their own certificates signed by a root CA. An attacker with low privileges can download the current CA certificate and Private Key (either the default ones or ones uploaded by administrators) and use those to decrypt HTTPS traffic, thus compromising confidentiality. Also, the default Private Key on this appliance is encrypted with a very weak passphrase. If an appliance uses the default Certificate and Private Key provided by Trend Micro, an attacker can simply download these and decrypt the Private Key using the default/weak passphrase.

    Published: 5 Apr 2017
    5.4
    Medium

    CVE-2017-6340

    Last Modified: 20 Apr 2025

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages.

    Published: 5 Apr 2017
    7.2
    High

    CVE-2016-9091

    Last Modified: 20 Apr 2025

    Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.

    Published: 5 Apr 2017
    7
    High

    CVE-2017-0325

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10 and Kernel 3.18. Android ID: A-33040280. References: N-CVE-2017-0325.

    Published: 5 Apr 2017
    7
    High

    CVE-2017-0327

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33893669. References: N-CVE-2017-0327.

    Published: 5 Apr 2017
    4.7
    Medium

    CVE-2017-0328

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33898322. References: N-CVE-2017-0328.

    Published: 5 Apr 2017
    7
    High

    CVE-2017-0329

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local malicious application to execute arbitrary code within the context of the boot and power management processor. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.18. Android ID:A-34115304. References: N-CVE-2017-0329.

    Published: 5 Apr 2017
    7
    High

    CVE-2017-0332

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33812508. References: N-CVE-2017-0332.

    Published: 5 Apr 2017
    7
    High

    CVE-2017-0339

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-27930566. References: N-CVE-2017-0339.

    Published: 5 Apr 2017
    4.7
    Medium

    CVE-2017-0330

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel 3.10. Android ID: A-33899858. References: N-CVE-2017-0330.

    Published: 5 Apr 2017
    8.8
    High

    CVE-2017-6956

    Last Modified: 20 Apr 2025

    On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition Information Element (FT-IE).

    Published: 5 Apr 2017
    6.8
    Medium

    CVE-2017-6975

    Last Modified: 20 Apr 2025

    Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access point. NOTE: because an operating system could potentially isolate itself from CVE-2017-6956 exploitation without patching Broadcom firmware functions, there is a separate CVE ID for the operating-system behavior.

    Published: 5 Apr 2017
    7.3
    High

    CVE-2017-7358

    Last Modified: 20 Apr 2025

    In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

    Published: 5 Apr 2017
    7.5
    High

    CVE-2017-5656

    Last Modified: 20 Apr 2025

    Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user.

    Published: 5 Apr 2017
    7.5
    High

    CVE-2017-7492

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7503. Reason: This candidate is a reservation duplicate of CVE-2017-7503. Notes: All CVE users should reference CVE-2017-7503 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 5 Apr 2017