CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-7614

    Last Modified: 20 Apr 2025

    elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.

    Published: 5 Apr 2017
    7.8
    High

    CVE-2017-7889

    Last Modified: 20 Apr 2025

    The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to read or write to kernel memory locations in the first megabyte (and bypass slab-allocation access restrictions) via an application that opens the /dev/mem file, related to arch/x86/mm/init.c and drivers/char/mem.c.

    Published: 5 Apr 2017
    7.8
    High

    CVE-2016-5870

    Last Modified: 20 Apr 2025

    The msm_ipc_router_close function in net/ipc_router/ipc_router_socket.c in the ipc_router component for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact by triggering failure of an accept system call for an AF_MSM_IPC socket.

    Published: 4 Apr 2017
    7.8
    High

    CVE-2016-3740

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF conversion. This is fixed in 8.0.

    Published: 4 Apr 2017
    7.5
    High

    CVE-2017-5649

    Last Modified: 20 Apr 2025

    Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote authenticated users with CLUSTER:READ but not DATA:READ permission to access the data browser page in Pulse and consequently execute an OQL query that exposes data stored in the cluster.

    Published: 4 Apr 2017
    5.3
    Medium

    CVE-2017-0360

    Last Modified: 20 Apr 2025

    file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root name but with a suffix" attack. NOTE: This vulnerability exists because of an incomplete fix for CVE-2016-1242.

    Published: 4 Apr 2017
    7.5
    High

    CVE-2015-1611

    Last Modified: 20 Apr 2025

    OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LLDP injection."

    Published: 4 Apr 2017
    7.5
    High

    CVE-2015-1612

    Last Modified: 20 Apr 2025

    OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reuse of LLDP packets, aka "LLDP Relay."

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7418

    Last Modified: 20 Apr 2025

    ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic link through the AllowChrootSymlinks configuration option, but checks only the last path component when enforcing AllowChrootSymlinks. Attackers with local access could bypass the AllowChrootSymlinks control by replacing a path component (other than the last one) with a symbolic link. The threat model includes an attacker who is not granted full filesystem access by a hosting provider, but can reconfigure the home directory of an FTP user.

    Published: 4 Apr 2017
    4.6
    Medium

    CVE-2017-5670

    Last Modified: 20 Apr 2025

    Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.

    Published: 4 Apr 2017
    4.6
    Medium

    CVE-2017-7305

    Last Modified: 20 Apr 2025

    Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for a bootloader password; however, this password is optional to meet different customers' needs

    Published: 4 Apr 2017
    6.4
    Medium

    CVE-2017-7306

    Last Modified: 20 Apr 2025

    Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers' needs

    Published: 4 Apr 2017
    6.8
    Medium

    CVE-2017-7307

    Last Modified: 20 Apr 2025

    Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.

    Published: 4 Apr 2017
    8.8
    High

    CVE-2017-7413

    Last Modified: 20 Apr 2025

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur if the attacker is an authenticated Horde Webmail user, has PGP features enabled in their preferences, and attempts to encrypt an email addressed to a maliciously crafted email address.

    Published: 4 Apr 2017
    7.5
    High

    CVE-2017-7414

    Last Modified: 20 Apr 2025

    In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occur if the user has PGP features enabled in the user's preferences, and has enabled the "Should PGP signed messages be automatically verified when viewed?" preference. To exploit this vulnerability, an attacker can send a PGP signed email (that is maliciously crafted) to the Horde user, who then must either view or preview it.

    Published: 4 Apr 2017
    7.8
    High

    CVE-2017-5683

    Last Modified: 20 Apr 2025

    Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user to gain system level access.

    Published: 4 Apr 2017
    8.8
    High

    CVE-2017-7398

    Last Modified: 20 Apr 2025

    D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

    Published: 4 Apr 2017
    8.2
    High

    CVE-2017-7228

    Last Modified: 20 Apr 2025

    An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7612

    Last Modified: 20 Apr 2025

    The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7613

    Last Modified: 20 Apr 2025

    elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

    Published: 4 Apr 2017
    6.5
    Medium

    CVE-2016-8629

    Last Modified: 21 Nov 2024

    Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.

    Published: 4 Apr 2017
    5.9
    Medium

    CVE-2017-2585

    Last Modified: 21 Nov 2024

    Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.

    Published: 4 Apr 2017
    6.5
    Medium

    CVE-2017-2672

    Last Modified: 21 Nov 2024

    A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.

    Published: 4 Apr 2017
    6.1
    Medium

    CVE-2017-7234

    Last Modified: 20 Apr 2025

    A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``django.views.static.serve()`` view could redirect to any other domain, aka an open redirect vulnerability.

    Published: 4 Apr 2017
    7.8
    High

    CVE-2017-7412

    Last Modified: 20 Apr 2025

    NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executing docker commands.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7607

    Last Modified: 20 Apr 2025

    The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7608

    Last Modified: 20 Apr 2025

    The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7609

    Last Modified: 20 Apr 2025

    elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7610

    Last Modified: 20 Apr 2025

    The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 4 Apr 2017
    5.5
    Medium

    CVE-2017-7611

    Last Modified: 20 Apr 2025

    The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

    Published: 4 Apr 2017
    6.1
    Medium

    CVE-2017-7233

    Last Modified: 20 Apr 2025

    Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the user to an "on success" URL. The security check for these redirects (namely ``django.utils.http.is_safe_url()``) considered some numeric URLs "safe" when they shouldn't be, aka an open redirect vulnerability. Also, if a developer relies on ``is_safe_url()`` to provide safe redirect targets and puts such a URL into a link, they could suffer from an XSS attack.

    Published: 4 Apr 2017
    9.8
    Critical

    CVE-2017-7410

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.

    Published: 3 Apr 2017
    3.9
    Low

    CVE-2017-5685

    Last Modified: 20 Apr 2025

    The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.

    Published: 3 Apr 2017
    3.9
    Low

    CVE-2017-5684

    Last Modified: 20 Apr 2025

    The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.

    Published: 3 Apr 2017
    3.9
    Low

    CVE-2017-5686

    Last Modified: 20 Apr 2025

    The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.

    Published: 3 Apr 2017
    7.5
    High

    CVE-2017-7397

    Last Modified: 20 Apr 2025

    BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.

    Published: 3 Apr 2017
    2.4
    Low

    CVE-2017-7407

    Last Modified: 16 Apr 2026

    The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.

    Published: 3 Apr 2017
    9.8
    Critical

    CVE-2017-7402

    Last Modified: 20 Apr 2025

    Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.

    Published: 3 Apr 2017
    9.8
    Critical

    CVE-2017-5642

    Last Modified: 20 Apr 2025

    During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

    Published: 3 Apr 2017
    9.8
    Critical

    CVE-2014-3928

    Last Modified: 20 Apr 2025

    Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.

    Published: 3 Apr 2017
    7.5
    High

    CVE-2014-3929

    Last Modified: 20 Apr 2025

    The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.

    Published: 3 Apr 2017
    7.5
    High

    CVE-2014-1677

    Last Modified: 20 Apr 2025

    Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.

    Published: 3 Apr 2017
    7.5
    High

    CVE-2014-3930

    Last Modified: 20 Apr 2025

    lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.

    Published: 3 Apr 2017
    9.8
    Critical

    CVE-2014-3927

    Last Modified: 20 Apr 2025

    mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.

    Published: 3 Apr 2017
    Unknown

    CVE-2016-1000268

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-7510. Reason: This candidate is a reservation duplicate of CVE-2016-7510. Notes: All CVE users should reference CVE-2016-7510 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Apr 2017
    7.5
    High

    CVE-2016-10211

    Last Modified: 20 Apr 2025

    libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function.

    Published: 3 Apr 2017
    7.5
    High

    CVE-2016-10222

    Last Modified: 20 Apr 2025

    runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "type confusion" in the JSON.stringify function.

    Published: 3 Apr 2017
    9.8
    Critical

    CVE-2016-10312

    Last Modified: 20 Apr 2025

    Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary commands via shell metacharacters to certain /goform/* pages.

    Published: 3 Apr 2017
    5.5
    Medium

    CVE-2017-7382

    Last Modified: 20 Apr 2025

    The PdfFontFactory.cpp:200:88 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

    Published: 3 Apr 2017
    5.5
    Medium

    CVE-2017-7383

    Last Modified: 20 Apr 2025

    The PdfFontFactory.cpp:195:62 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

    Published: 3 Apr 2017