CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-6465

    Last Modified: 20 Apr 2025

    Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.

    Published: 10 Mar 2017
    7.5
    High

    CVE-2017-2646

    Last Modified: 21 Nov 2024

    It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.

    Published: 10 Mar 2017
    6.1
    Medium

    CVE-2017-6797

    Last Modified: 20 Apr 2025

    A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.

    Published: 10 Mar 2017
    7.5
    High

    CVE-2017-2640

    Last Modified: 21 Nov 2024

    An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.

    Published: 10 Mar 2017
    9.8
    Critical

    CVE-2017-8399

    Last Modified: 20 Apr 2025

    PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."

    Published: 10 Mar 2017
    6.1
    Medium

    CVE-2017-6591

    Last Modified: 20 Apr 2025

    There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6589

    Last Modified: 20 Apr 2025

    EpicEditor through 0.2.3 has Cross-Site Scripting because of an insecure default marked.js configuration. An example attack vector is a crafted IMG element in an HTML document.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-6529

    Last Modified: 20 Apr 2025

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID parameter.

    Published: 9 Mar 2017
    9.8
    Critical

    CVE-2017-6526

    Last Modified: 20 Apr 2025

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).

    Published: 9 Mar 2017
    7.5
    High

    CVE-2017-6527

    Last Modified: 20 Apr 2025

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal attack allowing an unauthenticated attacker to access system files readable by the web server user (by using the viewAppletFsa.cgi seqID parameter).

    Published: 9 Mar 2017
    8.1
    High

    CVE-2017-6528

    Last Modified: 20 Apr 2025

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/spool/.pfile file).

    Published: 9 Mar 2017
    6.3
    Medium

    CVE-2017-6590

    Last Modified: 20 Apr 2025

    An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login screen to access local files and execute arbitrary commands as the lightdm user. The exploitation requires physical access to the locked computer and the Wi-Fi must be turned on. An access point that lets you use a certificate to login is required as well, but it's easy to create one. Then, it's possible to open a nautilus window and browse directories. One also can open some applications such as Firefox, which is useful for downloading malicious binaries.

    Published: 9 Mar 2017
    8.1
    High

    CVE-2017-6432

    Last Modified: 20 Apr 2025

    An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injections of packets, which allows creation of fully privileged new users, in addition to capture of sensitive information.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6575

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: member_id.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-6549

    Last Modified: 20 Apr 2025

    Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allows remote attackers to steal any active admin session by sending cgi_logout and asusrouter-Windows-IFTTT-1.0 in certain HTTP headers.

    Published: 9 Mar 2017
    7.5
    High

    CVE-2017-6552

    Last Modified: 20 Apr 2025

    Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting in a denial-of-service condition for telephone, Internet, and TV services.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6562

    Last Modified: 20 Apr 2025

    XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6573

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6561

    Last Modified: 20 Apr 2025

    XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6560

    Last Modified: 20 Apr 2025

    XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.

    Published: 9 Mar 2017
    5.4
    Medium

    CVE-2017-6555

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").

    Published: 9 Mar 2017
    5.4
    Medium

    CVE-2017-6556

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.

    Published: 9 Mar 2017
    9.8
    Critical

    CVE-2017-6558

    Last Modified: 20 Apr 2025

    iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6559

    Last Modified: 20 Apr 2025

    XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6570

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6571

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6572

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6577

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: list_id.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6578

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/subscriber_list.php with the POST Parameter: subscriber_email.

    Published: 9 Mar 2017
    6.1
    Medium

    CVE-2017-6547

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488 allows remote attackers to inject arbitrary JavaScript by requesting filenames longer than 50 characters.

    Published: 9 Mar 2017
    9.8
    Critical

    CVE-2017-6548

    Last Modified: 20 Apr 2025

    Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-AC750 routers with firmware before 3.0.0.4.380.7378; RT-AC68W routers with firmware before 3.0.0.4.380.7266; and RT-N600, RT-N12+ B1, RT-N11P B1, RT-N12VP B1, RT-N12E C1, RT-N300 B1, and RT-N12+ Pro routers with firmware before 3.0.0.4.380.9488; and Asuswrt-Merlin firmware before 380.65_2 allow remote attackers to execute arbitrary code on the router via a long host or port in crafted multicast messages.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6574

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.

    Published: 9 Mar 2017
    7.2
    High

    CVE-2017-6576

    Last Modified: 20 Apr 2025

    A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/campaign-delete.php with the GET Parameter: id.

    Published: 9 Mar 2017
    7.8
    High

    CVE-2017-5036

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file.

    Published: 9 Mar 2017
    6.3
    Medium

    CVE-2017-5038

    Last Modified: 20 Apr 2025

    Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension.

    Published: 9 Mar 2017
    4.3
    Medium

    CVE-2017-5040

    Last Modified: 20 Apr 2025

    V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neutering check, which allowed a remote attacker to read values in memory via a crafted HTML page.

    Published: 9 Mar 2017
    5.7
    Medium

    CVE-2017-5042

    Last Modified: 20 Apr 2025

    Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5051

    Last Modified: 20 Apr 2025

    An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

    Published: 9 Mar 2017
    6.4
    Medium

    CVE-2016-5483

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-3600. Reason: This candidate is a reservation duplicate of CVE-2017-3600. Notes: All CVE users should reference CVE-2017-3600 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5032

    Last Modified: 20 Apr 2025

    PDFium in Google Chrome prior to 57.0.2987.98 for Windows could be made to increment off the end of a buffer, which allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5034

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Linux and Windows allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

    Published: 9 Mar 2017
    7.8
    High

    CVE-2017-5039

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 9 Mar 2017
    6.3
    Medium

    CVE-2017-5044

    Last Modified: 20 Apr 2025

    Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5047

    Last Modified: 20 Apr 2025

    An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5048

    Last Modified: 20 Apr 2025

    An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5049

    Last Modified: 20 Apr 2025

    An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5050

    Last Modified: 20 Apr 2025

    An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5030

    Last Modified: 21 Apr 2026

    Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

    Published: 9 Mar 2017
    6.6
    Medium

    CVE-2017-3600

    Last Modified: 20 Apr 2025

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. Note: CVE-2017-3600 is equivalent to CVE-2016-5483. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

    Published: 9 Mar 2017
    8.8
    High

    CVE-2017-5029

    Last Modified: 20 Apr 2025

    The xsltAddTextString function in transform.c in libxslt 1.1.29, as used in Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android, lacked a check for integer overflow during a size calculation, which allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 9 Mar 2017