CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-2880

    Last Modified: 20 Apr 2025

    IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.

    Published: 1 Mar 2017
    5.4
    Medium

    CVE-2016-5932

    Last Modified: 20 Apr 2025

    IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.

    Published: 1 Mar 2017
    7.5
    High

    CVE-2017-3826

    Last Modified: 20 Apr 2025

    A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1a) could allow an unauthenticated, remote attacker to cause the device to hang or unexpectedly reload, causing a denial of service (DoS) condition. The vulnerability is due to incomplete validation of SCTP packets being monitored on the NGA data ports. An attacker could exploit this vulnerability by sending malformed SCTP packets on a network that is monitored by an NGA data port. SCTP packets addressed to the IP address of the NGA itself will not trigger this vulnerability. An exploit could allow the attacker to cause the appliance to become unresponsive or reload, causing a DoS condition. User interaction could be needed to recover the device using the reboot command from the CLI. The following Cisco NetFlow Generation Appliances are vulnerable: NGA 3140, NGA 3240, NGA 3340. Cisco Bug IDs: CSCvc83320.

    Published: 1 Mar 2017
    8.8
    High

    CVE-2016-5374

    Last Modified: 20 Apr 2025

    NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging improper handling of the owner_rights ACL entry.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9830

    Last Modified: 20 Apr 2025

    The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.

    Published: 1 Mar 2017
    7.5
    High

    CVE-2017-5995

    Last Modified: 20 Apr 2025

    The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 1 Mar 2017
    7.5
    High

    CVE-2016-6485

    Last Modified: 20 Apr 2025

    The __construct function in Framework/Encryption/Crypt.php in Magento 2 uses the PHP rand function to generate a random number for the initialization vector, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by guessing the value.

    Published: 1 Mar 2017
    7.4
    High

    CVE-2017-2685

    Last Modified: 20 Apr 2025

    Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack.

    Published: 1 Mar 2017
    6.5
    Medium

    CVE-2016-8508

    Last Modified: 20 Apr 2025

    Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.

    Published: 1 Mar 2017
    6.5
    Medium

    CVE-2016-8507

    Last Modified: 20 Apr 2025

    Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9824

    Last Modified: 20 Apr 2025

    Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5851

    Last Modified: 20 Apr 2025

    The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. NOTE: this typically has no risk; this crash of this command-line program has no further consequences for availability.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5855

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9819

    Last Modified: 20 Apr 2025

    libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9820

    Last Modified: 20 Apr 2025

    libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9821

    Last Modified: 20 Apr 2025

    Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9822

    Last Modified: 20 Apr 2025

    Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9823

    Last Modified: 20 Apr 2025

    libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9826

    Last Modified: 20 Apr 2025

    libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

    Published: 1 Mar 2017
    7.8
    High

    CVE-2017-5853

    Last Modified: 20 Apr 2025

    Integer overflow in base/PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5852

    Last Modified: 20 Apr 2025

    The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file.

    Published: 1 Mar 2017
    7.8
    High

    CVE-2017-5886

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the PoDoFo::PdfTokenizer::GetNextToken function in PdfTokenizer.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2016-9825

    Last Modified: 20 Apr 2025

    libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5666

    Last Modified: 20 Apr 2025

    The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5665

    Last Modified: 20 Apr 2025

    The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.

    Published: 1 Mar 2017
    5.5
    Medium

    CVE-2017-5854

    Last Modified: 20 Apr 2025

    base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.

    Published: 1 Mar 2017
    9.8
    Critical

    CVE-2017-1000056

    Last Modified: 20 Apr 2025

    Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.

    Published: 1 Mar 2017
    7.5
    High

    CVE-2017-1000048

    Last Modified: 20 Apr 2025

    the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.

    Published: 1 Mar 2017
    7.3
    High

    CVE-2017-5682

    Last Modified: 20 Apr 2025

    Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel Library, Intel Data Analytics Acceleration Library, and Intel Threading Building Blocks before 2017 Update 2 allows an attacker to launch a process with escalated privileges.

    Published: 28 Feb 2017
    5.4
    Medium

    CVE-2016-9259

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Feb 2017
    5.4
    Medium

    CVE-2016-9261

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tenable Log Correlation Engine (aka LCE) before 4.8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Feb 2017
    7.8
    High

    CVE-2016-8389

    Last Modified: 20 Apr 2025

    An exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will attempt to convert each character from a font into a polygon and then attempt to rasterize these shapes. As the application attempts to iterate through the rows and initializing the polygon shape in the buffer, it will write outside of the bounds of said buffer. This can lead to code execution under the context of the account running it.

    Published: 28 Feb 2017
    7.8
    High

    CVE-2016-8715

    Last Modified: 20 Apr 2025

    An exploitable heap corruption vulnerability exists in the loadTrailer functionality of Iceni Argus version 6.6.05. A specially crafted PDF file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide a malicious PDF file to trigger this vulnerability.

    Published: 28 Feb 2017
    7.8
    High

    CVE-2016-8388

    Last Modified: 20 Apr 2025

    An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will explicitly trust an index within the specific font object and use it to write the font's name to a single object within an array of objects.

    Published: 28 Feb 2017
    5.5
    Medium

    CVE-2017-6410

    Last Modified: 20 Apr 2025

    kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

    Published: 28 Feb 2017
    5.2
    Medium

    CVE-2017-2626

    Last Modified: 21 Nov 2024

    It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

    Published: 28 Feb 2017
    5.9
    Medium

    CVE-2017-2624

    Last Modified: 29 Aug 2025

    It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations return after an invalid byte is seen, this causes a time difference between a valid and invalid byte, which could allow an efficient brute force attack.

    Published: 28 Feb 2017
    7.5
    High

    CVE-2017-5982

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.

    Published: 28 Feb 2017
    6.5
    Medium

    CVE-2017-2625

    Last Modified: 21 Nov 2024

    It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

    Published: 28 Feb 2017
    7.8
    High

    CVE-2016-8385

    Last Modified: 20 Apr 2025

    An exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF to XML a stack variable will be left uninitialized which will later be used to fetch a length that is used in a copy operation. In most cases this will allow an aggressor to write outside the bounds of a stack buffer which is used to contain colors. This can lead to code execution under the context of the account running the tool.

    Published: 27 Feb 2017
    7.8
    High

    CVE-2016-8386

    Last Modified: 20 Apr 2025

    An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a PDF containing a malformed font to XML, the tool will attempt to use a size out of the font to search through a linked list of buffers to return. Due to a signedness issue, a buffer smaller than the requested size will be returned. Later when the tool tries to populate this buffer, the overflow will occur which can lead to code execution under the context of the user running the tool.

    Published: 27 Feb 2017
    7.8
    High

    CVE-2016-8387

    Last Modified: 20 Apr 2025

    An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF with an object encoded w/ multiple encoding types terminating with an LZW encoded type, an overflow may occur due to a lack of bounds checking by the LZW decoder. This can lead to code execution under the context of the account of the user running it.

    Published: 27 Feb 2017
    6.5
    Medium

    CVE-2016-8105

    Last Modified: 20 Apr 2025

    Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.

    Published: 27 Feb 2017
    Unknown

    CVE-2016-8509

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 27 Feb 2017
    Unknown

    CVE-2016-8510

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 27 Feb 2017
    8.8
    High

    CVE-2017-2682

    Last Modified: 20 Apr 2025

    The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform a Cross-Site Request Forgery (CSRF) attack, potentially allowing an attacker to execute administrative operations, provided the targeted user has an active session and is induced to trigger a malicious request.

    Published: 27 Feb 2017
    8.2
    High

    CVE-2017-2683

    Last Modified: 20 Apr 2025

    A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a persistent Cross-Site Scripting (XSS) attack, potentially resulting in obtaining administrative permissions.

    Published: 27 Feb 2017
    5.9
    Medium

    CVE-2017-6297

    Last Modified: 16 Sept 2026

    The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.

    Published: 27 Feb 2017
    7.5
    High

    CVE-2017-5927

    Last Modified: 20 Apr 2025

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

    Published: 27 Feb 2017
    3.7
    Low

    CVE-2017-5928

    Last Modified: 20 Apr 2025

    The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.

    Published: 27 Feb 2017