CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-6416

    Last Modified: 20 Apr 2025

    An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arbitrary code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

    Published: 6 Mar 2017
    7
    High

    CVE-2017-6874

    Last Modified: 20 Apr 2025

    Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.

    Published: 6 Mar 2017
    5.5
    Medium

    CVE-2017-8925

    Last Modified: 20 Apr 2025

    The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling.

    Published: 6 Mar 2017
    9.8
    Critical

    CVE-2017-5638

    Last Modified: 21 Apr 2026

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

    Published: 6 Mar 2017
    4.6
    Medium

    CVE-2017-8924

    Last Modified: 20 Apr 2025

    The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to obtain sensitive information (in the dmesg ringbuffer and syslog) from uninitialized kernel memory by using a crafted USB device (posing as an io_ti USB serial device) to trigger an integer underflow.

    Published: 6 Mar 2017
    6.1
    Medium

    CVE-2017-6446

    Last Modified: 20 Apr 2025

    XSS was discovered in Dotclear v2.11.2, affecting admin/blogs.php and admin/users.php with the sortby and order parameters.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6479

    Last Modified: 20 Apr 2025

    FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6490

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (cid, value, element, mode, tab, form_name, id) passed to the EPESI-master/modules/Utils/RecordBrowser/grid.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6484

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in INTER-Mediator 5.5. The vulnerabilities exist due to insufficient filtration of user-supplied data (c and cred) passed to the "INTER-Mediator-master/Auth_Support/PasswordReset/resetpassword.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6491

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, args, cid) passed to the EPESI-master/modules/Utils/Tooltip/req.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    8.1
    High

    CVE-2017-6445

    Last Modified: 20 Apr 2025

    The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6480

    Last Modified: 20 Apr 2025

    groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).

    Published: 5 Mar 2017
    Unknown

    CVE-2017-6482

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-6394. Reason: This candidate is a duplicate of CVE-2017-6394. Notes: All CVE users should reference CVE-2017-6394 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6485

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6486

    Last Modified: 20 Apr 2025

    A Cross-Site Scripting (XSS) issue was discovered in reasoncms before 4.7.1. The vulnerability exists due to insufficient filtration of user-supplied data (nyroModalSel) passed to the "reasoncms-master/www/nyroModal/demoSent.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6487

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (state, element, id, tab, cid) passed to the "EPESI-master/modules/Utils/RecordBrowser/favorites.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6488

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (visible, tab, cid) passed to the EPESI-master/modules/Utils/RecordBrowser/Filters/save_filters.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6489

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (element, state, cat, id, cid) passed to the EPESI-master/modules/Utils/Watchdog/subscribe.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    7.2
    High

    CVE-2017-6492

    Last Modified: 20 Apr 2025

    SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6481

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (instructions in app/admin/instructions/preview.php; subnetId in app/admin/powerDNS/refresh-ptr-records.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6483

    Last Modified: 20 Apr 2025

    Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 5 Mar 2017
    6.1
    Medium

    CVE-2017-6478

    Last Modified: 13 Feb 2026

    paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).

    Published: 5 Mar 2017
    7.5
    High

    CVE-2017-1000050

    Last Modified: 20 Apr 2025

    JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.

    Published: 5 Mar 2017
    7.5
    High

    CVE-2016-3127

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2016-8236

    Last Modified: 20 Apr 2025

    Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions earlier than 3.77.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2016-7969

    Last Modified: 20 Apr 2025

    The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."

    Published: 3 Mar 2017
    6.5
    Medium

    CVE-2016-6884

    Last Modified: 20 Apr 2025

    TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.

    Published: 3 Mar 2017
    8.2
    High

    CVE-2015-8813

    Last Modified: 20 Apr 2025

    The Page_Load function in Umbraco.Web/umbraco.presentation/umbraco/dashboard/FeedProxy.aspx.cs in Umbraco before 7.4.0 allows remote attackers to conduct server-side request forgery (SSRF) attacks via the url parameter.

    Published: 3 Mar 2017
    8.8
    High

    CVE-2015-8814

    Last Modified: 20 Apr 2025

    Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2015-8815

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Umbraco before 7.4.0 allow remote attackers to inject arbitrary web script or HTML via the name parameter to (1) the media page, (2) the developer data edit page, or (3) the form page.

    Published: 3 Mar 2017
    5.9
    Medium

    CVE-2016-6882

    Last Modified: 20 Apr 2025

    MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.

    Published: 3 Mar 2017
    5.9
    Medium

    CVE-2016-6883

    Last Modified: 20 Apr 2025

    MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2016-7407

    Last Modified: 20 Apr 2025

    The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.

    Published: 3 Mar 2017
    8.8
    High

    CVE-2016-7408

    Last Modified: 20 Apr 2025

    The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

    Published: 3 Mar 2017
    5.5
    Medium

    CVE-2016-7409

    Last Modified: 20 Apr 2025

    The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.

    Published: 3 Mar 2017
    7.5
    High

    CVE-2016-7970

    Last Modified: 20 Apr 2025

    Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 3 Mar 2017
    Unknown

    CVE-2016-7971

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 3 Mar 2017
    7.5
    High

    CVE-2016-7972

    Last Modified: 20 Apr 2025

    The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2016-7406

    Last Modified: 4 Nov 2025

    Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.

    Published: 3 Mar 2017
    8.8
    High

    CVE-2017-2290

    Last Modified: 20 Apr 2025

    On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This is resolved in mcollective-puppet-agent 1.12.1.

    Published: 3 Mar 2017
    7.3
    High

    CVE-2016-10205

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.

    Published: 3 Mar 2017
    8.8
    High

    CVE-2016-10206

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2016-10193

    Last Modified: 20 Apr 2025

    The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, save, bytes or bytes_wav method in lib/espeak/speech.rb.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2017-5615

    Last Modified: 20 Apr 2025

    cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.

    Published: 3 Mar 2017
    5.9
    Medium

    CVE-2017-5831

    Last Modified: 20 Apr 2025

    Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.

    Published: 3 Mar 2017
    5.4
    Medium

    CVE-2017-5832

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.

    Published: 3 Mar 2017
    9.8
    Critical

    CVE-2016-10194

    Last Modified: 20 Apr 2025

    The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2) to_mp3 method in lib/festivaltts4r/festival4r.rb.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2016-10201

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2016-10202

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php.

    Published: 3 Mar 2017
    6.1
    Medium

    CVE-2016-10203

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor.

    Published: 3 Mar 2017