CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-2224

    Last Modified: 20 Apr 2025

    The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply.

    Published: 24 Mar 2017
    5.4
    Medium

    CVE-2017-7257

    Last Modified: 20 Apr 2025

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.

    Published: 24 Mar 2017
    5.4
    Medium

    CVE-2017-7255

    Last Modified: 20 Apr 2025

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.

    Published: 24 Mar 2017
    5.4
    Medium

    CVE-2017-7256

    Last Modified: 20 Apr 2025

    XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_summary parameter. Someone must login to conduct the attack.

    Published: 24 Mar 2017
    9.8
    Critical

    CVE-2016-10128

    Last Modified: 20 Apr 2025

    Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

    Published: 24 Mar 2017
    9.8
    Critical

    CVE-2016-10133

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments to lightweight functions.

    Published: 24 Mar 2017
    7.5
    High

    CVE-2016-10129

    Last Modified: 20 Apr 2025

    The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

    Published: 24 Mar 2017
    5.9
    Medium

    CVE-2016-10130

    Last Modified: 20 Apr 2025

    The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2016-3178

    Last Modified: 20 Apr 2025

    The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2016-3179

    Last Modified: 20 Apr 2025

    The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling.

    Published: 24 Mar 2017
    9.8
    Critical

    CVE-2016-6206

    Last Modified: 20 Apr 2025

    Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet.

    Published: 24 Mar 2017
    7.5
    High

    CVE-2017-7243

    Last Modified: 20 Apr 2025

    Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.

    Published: 24 Mar 2017
    7.5
    High

    CVE-2017-7240

    Last Modified: 20 Apr 2025

    An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks. A Proof of Concept is GET /../../../../../../../../../../../../etc/shadow HTTP/1.1. This affects PG8527 devices 2.02 before 2.12, PG8527 devices 2.51 before 2.61, PG8527 devices 2.52 before 2.62, PG8527 devices 2.54 before 2.64, PG8528 devices 2.02 before 2.12, PG8528 devices 2.51 before 2.61, PG8528 devices 2.52 before 2.62, PG8528 devices 2.54 before 2.64, PG8535 devices 1.00 before 1.10, PG8535 devices 1.04 before 1.14, PG8536 devices 1.10 before 1.20, and PG8536 devices 1.14 before 1.24.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2017-5644

    Last Modified: 20 Apr 2025

    Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2015-8678

    Last Modified: 20 Apr 2025

    The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows remote attackers to cause a denial of service (crash) via a crafted application.

    Published: 24 Mar 2017
    8.8
    High

    CVE-2017-5869

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

    Published: 24 Mar 2017
    8.8
    High

    CVE-2017-6087

    Last Modified: 20 Apr 2025

    EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.

    Published: 24 Mar 2017
    8.8
    High

    CVE-2017-6369

    Last Modified: 10 Oct 2025

    Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticated users to execute code by using a 'system' entrypoint from fbudf.so.

    Published: 24 Mar 2017
    Unknown

    CVE-2017-2577

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 24 Mar 2017
    8.8
    High

    CVE-2017-5198

    Last Modified: 20 Apr 2025

    SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.

    Published: 24 Mar 2017
    8.8
    High

    CVE-2017-5199

    Last Modified: 20 Apr 2025

    The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.

    Published: 24 Mar 2017
    5.9
    Medium

    CVE-2017-6507

    Last Modified: 20 Apr 2025

    An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to handle 'restart' operations removing AppArmor profiles that aren't found in the typical filesystem locations, such as /etc/apparmor.d/. Userspace projects that manage their own AppArmor profiles in atypical directories, such as what's done by LXD and Docker, are affected by this flaw in the AppArmor init script logic.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2017-2671

    Last Modified: 20 Apr 2025

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2017-7585

    Last Modified: 20 Apr 2025

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

    Published: 24 Mar 2017
    9.8
    Critical

    CVE-2017-8105

    Last Modified: 20 Apr 2025

    FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.

    Published: 24 Mar 2017
    5.5
    Medium

    CVE-2017-7261

    Last Modified: 20 Apr 2025

    The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value of certain levels data, which allows local users to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and possibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.

    Published: 24 Mar 2017
    7.1
    High

    CVE-2017-7976

    Last Modified: 20 Apr 2025

    Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of sensitive information from process memory.

    Published: 24 Mar 2017
    9.8
    Critical

    CVE-2018-7548

    Last Modified: 21 Nov 2024

    In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.

    Published: 24 Mar 2017
    6.1
    Medium

    CVE-2017-7251

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtration of user-supplied data (preview) passed to the "pi-develop/www/script/editor/markitup/preview/markdown.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 23 Mar 2017
    6.1
    Medium

    CVE-2017-7247

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (torrents, size) passed to the 'Gazelle-master/sections/tools/managers/multiple_freeleech.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 23 Mar 2017
    6.1
    Medium

    CVE-2017-7248

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (type) passed to the 'Gazelle-master/sections/better/transcode.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 23 Mar 2017
    6.1
    Medium

    CVE-2017-7249

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insufficient filtration of user-supplied data (action, userid) passed to the 'Gazelle-master/sections/tools/data/ocelot_info.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 23 Mar 2017
    6.1
    Medium

    CVE-2017-7250

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient filtration of user-supplied data (action) passed to the 'Gazelle-master/sections/tools/finances/bitcoin_balance.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 23 Mar 2017
    8.8
    High

    CVE-2015-8624

    Last Modified: 20 Apr 2025

    The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 does not perform token comparison in constant time before determining if a debugging message should be logged, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8623.

    Published: 23 Mar 2017
    3.1
    Low

    CVE-2013-6446

    Last Modified: 20 Apr 2025

    The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job information by leveraging failure to enforce job ACLs.

    Published: 23 Mar 2017
    6.5
    Medium

    CVE-2014-0229

    Last Modified: 20 Apr 2025

    Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows remote authenticated users to cause a denial of service (DataNodes shutdown) or perform unnecessary operations by issuing a command.

    Published: 23 Mar 2017
    3.3
    Low

    CVE-2015-2263

    Last Modified: 20 Apr 2025

    Cloudera Manager 4.x, 5.0.x before 5.0.6, 5.1.x before 5.1.5, 5.2.x before 5.2.5, and 5.3.x before 5.3.3 uses global read permissions for files in its configuration directory when starting YARN NodeManager, which allows local users to obtain sensitive information by reading the files, as demonstrated by yarn.keytab or ssl-server.xml in /var/run/cloudera-scm-agent/process.

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2015-5729

    Last Modified: 20 Apr 2025

    The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack.

    Published: 23 Mar 2017
    8.8
    High

    CVE-2015-8623

    Last Modified: 20 Apr 2025

    The User::matchEditToken function in includes/User.php in MediaWiki before 1.23.12 and 1.24.x before 1.24.5 does not perform token comparison in constant time before returning, which allows remote attackers to guess the edit token and bypass CSRF protection via a timing attack, a different vulnerability than CVE-2015-8624.

    Published: 23 Mar 2017
    7.5
    High

    CVE-2015-8625

    Last Modified: 20 Apr 2025

    MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly sanitize parameters when calling the cURL library, which allows remote attackers to read arbitrary files via an @ (at sign) character in unspecified POST array parameters.

    Published: 23 Mar 2017
    5.4
    Medium

    CVE-2015-8687

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Alcatel-Lucent Motive Home Device Manager (HDM) before 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceTypeID parameter to DeviceType/getDeviceType.do; the (2) policyActionClass or (3) policyActionName parameter to PolicyAction/findPolicyActions.do; the deviceID parameter to (4) SingleDeviceMgmt/getDevice.do or (5) device/editDevice.do; the operation parameter to (6) ajax.do or (7) xmlHttp.do; or the (8) policyAction, (9) policyClass, or (10) policyName parameter to policy/findPolicies.do.

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2017-6517

    Last Modified: 20 Apr 2025

    Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded by Skype. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.The specific flaw exists within the handling of DLL (api-ms-win-core-winrt-string-l1-1-0.dll) loading by the Skype.exe process.

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2015-0855

    Last Modified: 20 Apr 2025

    The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.

    Published: 23 Mar 2017
    3.1
    Low

    CVE-2015-4078

    Last Modified: 20 Apr 2025

    Cloudera Navigator 2.2.x before 2.2.4 and 2.3.x before 2.3.3 include support for SSLv3 when configured to use SSL/TLS, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2015-4166

    Last Modified: 20 Apr 2025

    Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key.

    Published: 23 Mar 2017
    6.1
    Medium

    CVE-2015-8622

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1, when is configured with a relative URL, allows remote authenticated users to inject arbitrary web script or HTML via wikitext, as demonstrated by a wikilink to a page named "javascript:alert('XSS!')."

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2015-8626

    Last Modified: 20 Apr 2025

    The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 23 Mar 2017
    5.3
    Medium

    CVE-2015-8627

    Last Modified: 20 Apr 2025

    MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero-padded octets, which might allow remote attackers to bypass intended access restrictions by using an IP address that was not supposed to have been allowed.

    Published: 23 Mar 2017
    5.3
    Medium

    CVE-2015-8628

    Last Modified: 20 Apr 2025

    The (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions, (4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 allow remote attackers to obtain sensitive user login information via crafted links combined with page view statistics.

    Published: 23 Mar 2017
    9.8
    Critical

    CVE-2017-6895

    Last Modified: 20 Apr 2025

    USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.

    Published: 23 Mar 2017