CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-5358

    Last Modified: 20 Apr 2025

    Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.

    Published: 15 Mar 2017
    7.5
    High

    CVE-2017-5359

    Last Modified: 20 Apr 2025

    EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.

    Published: 15 Mar 2017
    9.8
    Critical

    CVE-2017-5496

    Last Modified: 20 Apr 2025

    Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.

    Published: 15 Mar 2017
    5.3
    Medium

    CVE-2017-5537

    Last Modified: 20 Apr 2025

    The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.

    Published: 15 Mar 2017
    7.1
    High

    CVE-2017-5580

    Last Modified: 20 Apr 2025

    The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.

    Published: 15 Mar 2017
    7.3
    High

    CVE-2017-6189

    Last Modified: 20 Apr 2025

    Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in the current working directory of the Kindle Setup installer.

    Published: 15 Mar 2017
    7.8
    High

    CVE-2017-6429

    Last Modified: 20 Apr 2025

    Buffer overflow in the tcpcapinfo utility in Tcpreplay before 4.2.0 Beta 1 allows remote attackers to have unspecified impact via a pcap file with an over-size packet.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6430

    Last Modified: 20 Apr 2025

    The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted filter.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6443

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.

    Published: 15 Mar 2017
    Unknown

    CVE-2016-8002

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-5938

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-5993

    Last Modified: 20 Apr 2025

    Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.

    Published: 15 Mar 2017
    8.8
    High

    CVE-2017-6366

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi. NOTE: this issue can be combined with CVE-2017-6334 to execute arbitrary code remotely.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6847

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6840

    Last Modified: 20 Apr 2025

    The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6848

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.4
    Medium

    CVE-2017-5584

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-5583

    Last Modified: 20 Apr 2025

    The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-6210

    Last Modified: 20 Apr 2025

    The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero).

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-6317

    Last Modified: 20 Apr 2025

    Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-6386

    Last Modified: 20 Apr 2025

    Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS commands.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6841

    Last Modified: 20 Apr 2025

    The GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement function in graphicsstack.h in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6842

    Last Modified: 20 Apr 2025

    The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    7.8
    High

    CVE-2017-6843

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.

    Published: 15 Mar 2017
    7.8
    High

    CVE-2017-6844

    Last Modified: 20 Apr 2025

    Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6845

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfColor::operator function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6846

    Last Modified: 20 Apr 2025

    The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-6849

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2017-5994

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.

    Published: 15 Mar 2017
    7.8
    High

    CVE-2017-6060

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.

    Published: 15 Mar 2017
    6.5
    Medium

    CVE-2017-6209

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties.

    Published: 15 Mar 2017
    5.8
    Medium

    CVE-2017-7200

    Last Modified: 17 Sept 2026

    An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6905

    Last Modified: 20 Apr 2025

    An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the "concrete5-legacy-master/web/concrete/tools/files/search_dialog.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6906

    Last Modified: 20 Apr 2025

    An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6907

    Last Modified: 20 Apr 2025

    An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the "Open.GL-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6908

    Last Modified: 20 Apr 2025

    An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 15 Mar 2017
    6.1
    Medium

    CVE-2017-6909

    Last Modified: 20 Apr 2025

    An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 15 Mar 2017
    7.8
    High

    CVE-2017-7980

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation.

    Published: 15 Mar 2017
    5.5
    Medium

    CVE-2013-7461

    Last Modified: 20 Apr 2025

    A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.

    Published: 14 Mar 2017
    6.5
    Medium

    CVE-2016-8005

    Last Modified: 20 Apr 2025

    File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a forged attached filename that uses a null byte within the filename extension.

    Published: 14 Mar 2017
    6.3
    Medium

    CVE-2016-8007

    Last Modified: 20 Apr 2025

    Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific conditions.

    Published: 14 Mar 2017
    4.1
    Medium

    CVE-2016-8017

    Last Modified: 20 Apr 2025

    Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.

    Published: 14 Mar 2017
    6.2
    Medium

    CVE-2016-8025

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.

    Published: 14 Mar 2017
    5.9
    Medium

    CVE-2014-9920

    Last Modified: 20 Apr 2025

    Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, and 6.1.3 before hotfix 357 and earlier allows attackers to create a malformed Windows binary that is considered non-executable and is not protected through the whitelisting protection feature via a specific set of circumstances.

    Published: 14 Mar 2017
    7
    High

    CVE-2015-8991

    Last Modified: 20 Apr 2025

    Malicious file execution vulnerability in Intel Security McAfee Security Scan+ (MSS+) before 3.11.266.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.

    Published: 14 Mar 2017
    3.4
    Low

    CVE-2016-8016

    Last Modified: 20 Apr 2025

    Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter.

    Published: 14 Mar 2017
    8.1
    High

    CVE-2016-8024

    Last Modified: 20 Apr 2025

    Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to obtain sensitive information via the server HTTP response spoofing.

    Published: 14 Mar 2017
    5.5
    Medium

    CVE-2013-7460

    Last Modified: 20 Apr 2025

    A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.

    Published: 14 Mar 2017
    7.5
    High

    CVE-2013-7462

    Last Modified: 20 Apr 2025

    A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated users to view contents of arbitrary system files that did not have file system level read access restrictions via a null-byte injection exploit.

    Published: 14 Mar 2017
    9.8
    Critical

    CVE-2014-9921

    Last Modified: 20 Apr 2025

    Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration error.

    Published: 14 Mar 2017