CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2015-0864

    Last Modified: 20 Apr 2025

    Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.

    Published: 27 Mar 2017
    6.1
    Medium

    CVE-2015-8010

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.

    Published: 27 Mar 2017
    7.8
    High

    CVE-2016-10225

    Last Modified: 20 Apr 2025

    The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.

    Published: 27 Mar 2017
    9.8
    Critical

    CVE-2017-6542

    Last Modified: 20 Apr 2025

    The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.

    Published: 27 Mar 2017
    6.1
    Medium

    CVE-2017-7271

    Last Modified: 20 Apr 2025

    Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.

    Published: 27 Mar 2017
    7.5
    High

    CVE-2017-7183

    Last Modified: 20 Apr 2025

    The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.

    Published: 27 Mar 2017
    9.8
    Critical

    CVE-2017-7191

    Last Modified: 20 Apr 2025

    The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.

    Published: 27 Mar 2017
    7.8
    High

    CVE-2015-8026

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the verify_vbr_checksum function in exfatfsck in exfat-utils before 1.2.1 allows remote attackers to cause a denial of service (infinite loop) or possibly execute arbitrary code via a crafted filesystem.

    Published: 27 Mar 2017
    4.3
    Medium

    CVE-2015-8309

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."

    Published: 27 Mar 2017
    5.4
    Medium

    CVE-2015-8310

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.

    Published: 27 Mar 2017
    7.5
    High

    CVE-2017-5850

    Last Modified: 20 Apr 2025

    httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.

    Published: 27 Mar 2017
    5.5
    Medium

    CVE-2016-7474

    Last Modified: 20 Apr 2025

    In some cases the MCPD binary cache in F5 BIG-IP devices may allow a user with Advanced Shell access, or privileges to generate a qkview, to temporarily obtain normally unrecoverable information.

    Published: 27 Mar 2017
    5.4
    Medium

    CVE-2017-6878

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.

    Published: 27 Mar 2017
    8.1
    High

    CVE-2017-6957

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feature is enabled in RAM, allows remote attackers to execute arbitrary code via a crafted reassociation response frame with a Cisco IE (156).

    Published: 27 Mar 2017
    8.8
    High

    CVE-2017-6002

    Last Modified: 20 Apr 2025

    Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.

    Published: 27 Mar 2017
    9.8
    Critical

    CVE-2017-7269

    Last Modified: 21 Apr 2026

    Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

    Published: 27 Mar 2017
    6.1
    Medium

    CVE-2017-6067

    Last Modified: 20 Apr 2025

    Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.

    Published: 27 Mar 2017
    6.1
    Medium

    CVE-2017-6003

    Last Modified: 20 Apr 2025

    dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.

    Published: 27 Mar 2017
    Unknown

    CVE-2017-6006

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Mar 2017
    9.8
    Critical

    CVE-2017-6013

    Last Modified: 20 Apr 2025

    Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.

    Published: 27 Mar 2017
    8.8
    High

    CVE-2017-6066

    Last Modified: 20 Apr 2025

    Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.

    Published: 27 Mar 2017
    8.8
    High

    CVE-2017-6068

    Last Modified: 20 Apr 2025

    Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.

    Published: 27 Mar 2017
    8.8
    High

    CVE-2017-6069

    Last Modified: 20 Apr 2025

    Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.

    Published: 27 Mar 2017
    6.5
    Medium

    CVE-2017-7395

    Last Modified: 20 Apr 2025

    In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.

    Published: 27 Mar 2017
    5.5
    Medium

    CVE-2017-7275

    Last Modified: 20 Apr 2025

    The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows remote attackers to cause a denial of service (attempted large memory allocation and application crash) via a crafted file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862 and CVE-2016-8866.

    Published: 27 Mar 2017
    7.8
    High

    CVE-2017-7975

    Last Modified: 20 Apr 2025

    Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function in jbig2_huffman.c during operations on a crafted JBIG2 file, leading to a denial of service (application crash) or possibly execution of arbitrary code.

    Published: 27 Mar 2017
    8.1
    High

    CVE-2017-2667

    Last Modified: 21 Nov 2024

    Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.

    Published: 27 Mar 2017
    5.3
    Medium

    CVE-2017-5653

    Last Modified: 20 Apr 2025

    JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.

    Published: 27 Mar 2017
    7.4
    High

    CVE-2017-7272

    Last Modified: 20 Apr 2025

    PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.

    Published: 27 Mar 2017
    6.6
    Medium

    CVE-2017-7273

    Last Modified: 20 Apr 2025

    The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report.

    Published: 27 Mar 2017
    8.8
    High

    CVE-2017-7393

    Last Modified: 20 Apr 2025

    In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.

    Published: 27 Mar 2017
    7.5
    High

    CVE-2017-7396

    Last Modified: 20 Apr 2025

    In TigerVNC 1.7.1 (CConnection.cxx CConnection::CConnection), an unauthenticated client can cause a small memory leak in the server.

    Published: 27 Mar 2017
    5.9
    Medium

    CVE-2017-5622

    Last Modified: 20 Apr 2025

    With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the device, in order to further exploit other vulnerabilities and/or exfiltrate sensitive information.

    Published: 26 Mar 2017
    9.8
    Critical

    CVE-2017-2641

    Last Modified: 20 Apr 2025

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

    Published: 26 Mar 2017
    5.3
    Medium

    CVE-2017-2643

    Last Modified: 20 Apr 2025

    In Moodle 3.2.x, global search displays user names for unauthenticated users.

    Published: 26 Mar 2017
    6.1
    Medium

    CVE-2017-2644

    Last Modified: 20 Apr 2025

    In Moodle 3.x, XSS can occur via evidence of prior learning.

    Published: 26 Mar 2017
    6.1
    Medium

    CVE-2017-2645

    Last Modified: 20 Apr 2025

    In Moodle 3.x, XSS can occur via attachments to evidence of prior learning.

    Published: 26 Mar 2017
    8.8
    High

    CVE-2016-10273

    Last Modified: 20 Apr 2025

    Multiple stack buffer overflow vulnerabilities in Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary code or crash the web service via the (1) ateFunc, (2) ateGain, (3) ateTxCount, (4) ateChan, (5) ateRate, (6) ateMacID, (7) e2pTxPower1, (8) e2pTxPower2, (9) e2pTxPower3, (10) e2pTxPower4, (11) e2pTxPower5, (12) e2pTxPower6, (13) e2pTxPower7, (14) e2pTx2Power1, (15) e2pTx2Power2, (16) e2pTx2Power3, (17) e2pTx2Power4, (18) e2pTx2Power5, (19) e2pTx2Power6, (20) e2pTx2Power7, (21) ateTxFreqOffset, (22) ateMode, (23) ateBW, (24) ateAntenna, (25) e2pTxFreqOffset, (26) e2pTxPwDeltaB, (27) e2pTxPwDeltaG, (28) e2pTxPwDeltaMix, (29) e2pTxPwDeltaN, and (30) readE2P parameters of the /goform/formWlanMP endpoint.

    Published: 26 Mar 2017
    7.8
    High

    CVE-2017-7263

    Last Modified: 20 Apr 2025

    The bm_readbody_bmp function in bitmap_io.c in Potrace 1.14 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8698.

    Published: 26 Mar 2017
    6.1
    Medium

    CVE-2017-7266

    Last Modified: 20 Apr 2025

    Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.

    Published: 26 Mar 2017
    5.3
    Medium

    CVE-2017-7264

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the fz_subsample_pixmap function in fitz/pixmap.c in Artifex MuPDF 1.10a allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted document.

    Published: 26 Mar 2017
    8.8
    High

    CVE-2017-0367

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 contains an unsafe use of temporary directory, where having LocalisationCache directory default to system tmp directory is insecure.

    Published: 26 Mar 2017
    5.5
    Medium

    CVE-2017-7586

    Last Modified: 20 Apr 2025

    In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

    Published: 26 Mar 2017
    9.8
    Critical

    CVE-2017-8287

    Last Modified: 20 Apr 2025

    FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.

    Published: 26 Mar 2017
    Unknown

    CVE-2017-7259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Mar 2017
    4
    Medium

    CVE-2017-11671

    Last Modified: 20 Apr 2025

    Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

    Published: 25 Mar 2017
    5.5
    Medium

    CVE-2017-7262

    Last Modified: 20 Apr 2025

    The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.

    Published: 25 Mar 2017
    7.8
    High

    CVE-2017-18234

    Last Modified: 21 Nov 2024

    An issue was discovered in Exempi before 2.4.3. It allows remote attackers to cause a denial of service (invalid memcpy with resultant use-after-free) or possibly have unspecified other impact via a .pdf file containing JPEG data, related to XMPFiles/source/FormatSupport/ReconcileTIFF.cpp, XMPFiles/source/FormatSupport/TIFF_MemoryReader.cpp, and XMPFiles/source/FormatSupport/TIFF_Support.hpp.

    Published: 25 Mar 2017
    7.5
    High

    CVE-2016-2225

    Last Modified: 20 Apr 2025

    The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 24 Mar 2017
    7.5
    High

    CVE-2016-10132

    Last Modified: 20 Apr 2025

    regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.

    Published: 24 Mar 2017