CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2017-7322

    Last Modified: 20 Apr 2025

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2017-7324

    Last Modified: 20 Apr 2025

    setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2016-10308

    Last Modified: 20 Apr 2025

    Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable password that is the same across all devices. This account is accessible via both SSH and the device's web interface and grants access to the underlying embedded Linux OS on the device, allowing full control over it.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2016-10309

    Last Modified: 20 Apr 2025

    In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALBATROSS cookie with the value 0-4-11 to their browser.

    Published: 30 Mar 2017
    7.2
    High

    CVE-2017-7290

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2017-7321

    Last Modified: 20 Apr 2025

    setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.

    Published: 30 Mar 2017
    8.1
    High

    CVE-2017-7323

    Last Modified: 20 Apr 2025

    The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism.

    Published: 30 Mar 2017
    9.8
    Critical

    CVE-2017-7318

    Last Modified: 20 Apr 2025

    Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with no authentication.

    Published: 30 Mar 2017
    6.1
    Medium

    CVE-2017-7320

    Last Modified: 20 Apr 2025

    setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct HTTP Response Splitting attacks with resultant XSS, via an invalid parameter value.

    Published: 30 Mar 2017
    7.1
    High

    CVE-2017-1000061

    Last Modified: 20 Apr 2025

    xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service

    Published: 30 Mar 2017
    0
    Low

    CVE-2017-7319

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 30 Mar 2017
    7.1
    High

    CVE-2017-7885

    Last Modified: 20 Apr 2025

    Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a during operation on a crafted .jb2 file.

    Published: 30 Mar 2017
    5.5
    Medium

    CVE-2017-7346

    Last Modified: 20 Apr 2025

    The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for a /dev/dri/renderD* device.

    Published: 30 Mar 2017
    7
    High

    CVE-2017-4977

    Last Modified: 20 Apr 2025

    EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2017-4980

    Last Modified: 20 Apr 2025

    EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system. Affected versions are 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3, and 8.0.0 - 8.0.0.1.

    Published: 29 Mar 2017
    7.8
    High

    CVE-2017-7310

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.

    Published: 29 Mar 2017
    9.8
    Critical

    CVE-2014-3582

    Last Modified: 20 Apr 2025

    In Ambari 1.2.0 through 2.2.2, it may be possible to execute arbitrary system commands on the Ambari Server host while generating SSL certificates for hosts in an Ambari cluster.

    Published: 29 Mar 2017
    5.5
    Medium

    CVE-2016-4976

    Last Modified: 20 Apr 2025

    Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2017-7258

    Last Modified: 20 Apr 2025

    HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Path Traversal, as demonstrated by reading core-emli/Storage. The affected versions are eMLi School Management 1.0, eMLi College Campus Management 1.0, and eMLi University Management 1.0.

    Published: 29 Mar 2017
    9.8
    Critical

    CVE-2016-9924

    Last Modified: 20 Apr 2025

    Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-5671

    Last Modified: 20 Apr 2025

    Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2015-4556

    Last Modified: 20 Apr 2025

    The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).

    Published: 29 Mar 2017
    6.1
    Medium

    CVE-2016-6846

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web before 7.6.2-rev16, 7.8.0 before 7.8.0-rev10, and 7.8.2 before 7.8.2-rev5; and Documentconverter-API before 7.8.2-rev5 allows remote attackers to inject arbitrary web script or HTML.

    Published: 29 Mar 2017
    5.4
    Medium

    CVE-2017-5900

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 parameter to hdd.htm.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2017-7285

    Last Modified: 20 Apr 2025

    A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.

    Published: 29 Mar 2017
    5.4
    Medium

    CVE-2017-7298

    Last Modified: 20 Apr 2025

    In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.

    Published: 29 Mar 2017
    Unknown

    CVE-2017-2655

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Mar 2017
    5.4
    Medium

    CVE-2017-6864

    Last Modified: 20 Apr 2025

    The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks.

    Published: 29 Mar 2017
    6.1
    Medium

    CVE-2017-2687

    Last Modified: 20 Apr 2025

    Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-2689

    Last Modified: 20 Apr 2025

    Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or change configuration settings.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-2688

    Last Modified: 20 Apr 2025

    The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to perform actions with the privileges of an authenticated user, provided the targeted user has an active session and is induced into clicking on a malicious link or into visiting a malicious website, aka CSRF.

    Published: 29 Mar 2017
    6.5
    Medium

    CVE-2017-2686

    Last Modified: 20 Apr 2025

    Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and access sensitive information.

    Published: 29 Mar 2017
    10
    Critical

    CVE-2017-5226

    Last Modified: 20 Apr 2025

    When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2017-7392

    Last Modified: 20 Apr 2025

    In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-5054

    Last Modified: 20 Apr 2025

    An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to obtain heap memory contents via a crafted HTML page.

    Published: 29 Mar 2017
    7.5
    High

    CVE-2017-7394

    Last Modified: 20 Apr 2025

    In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.

    Published: 29 Mar 2017
    8.1
    High

    CVE-2017-3204

    Last Modified: 20 Apr 2025

    The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.

    Published: 29 Mar 2017
    6.1
    Medium

    CVE-2017-4967

    Last Modified: 20 Apr 2025

    An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-5055

    Last Modified: 20 Apr 2025

    A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 Mar 2017
    0
    Low

    CVE-2017-7286

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-7297

    Last Modified: 20 Apr 2025

    Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.

    Published: 29 Mar 2017
    9.8
    Critical

    CVE-2017-2628

    Last Modified: 21 Nov 2024

    curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue was introduced in RHEL 6.7 and affects RHEL 6 curl only.

    Published: 29 Mar 2017
    6.1
    Medium

    CVE-2017-4965

    Last Modified: 20 Apr 2025

    An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. Several forms in the RabbitMQ management UI are vulnerable to XSS attacks.

    Published: 29 Mar 2017
    7.8
    High

    CVE-2017-4966

    Last Modified: 20 Apr 2025

    An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-5052

    Last Modified: 20 Apr 2025

    An incorrect assumption about block structure in Blink in Google Chrome prior to 57.0.2987.133 for Mac, Windows, and Linux, and 57.0.2987.132 for Android, allowed a remote attacker to potentially exploit memory corruption via a crafted HTML page that triggers improper casting.

    Published: 29 Mar 2017
    9.6
    Critical

    CVE-2017-5053

    Last Modified: 20 Apr 2025

    An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.

    Published: 29 Mar 2017
    8.8
    High

    CVE-2017-5056

    Last Modified: 20 Apr 2025

    A use after free in Blink in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 Mar 2017
    7.8
    High

    CVE-2017-6419

    Last Modified: 20 Apr 2025

    mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

    Published: 29 Mar 2017
    7.8
    High

    CVE-2017-7308

    Last Modified: 20 Apr 2025

    The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.

    Published: 29 Mar 2017
    9.8
    Critical

    CVE-2016-6807

    Last Modified: 20 Apr 2025

    Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

    Published: 28 Mar 2017