CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2017-6341

    Last Modified: 20 Apr 2025

    Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 send cleartext passwords in response to requests from the Web Page, Mobile Application, and Desktop Application interfaces, which allows remote attackers to obtain sensitive information by sniffing the network, a different vulnerability than CVE-2013-6117.

    Published: 27 Feb 2017
    9.8
    Critical

    CVE-2017-6342

    Last Modified: 20 Apr 2025

    An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19. When SmartPSS Software is launched, while on the login screen, the software in the background automatically logs in as admin. This allows sniffing sensitive information identified in CVE-2017-6341 without prior knowledge of the password. This is a different vulnerability than CVE-2013-6117.

    Published: 27 Feb 2017
    8.1
    High

    CVE-2017-6343

    Last Modified: 20 Apr 2025

    The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2017-01-19 allows remote attackers to obtain login access by leveraging knowledge of the MD5 Admin Hash without knowledge of the corresponding password, a different vulnerability than CVE-2013-6117.

    Published: 27 Feb 2017
    5.9
    Medium

    CVE-2017-6344

    Last Modified: 20 Apr 2025

    XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.

    Published: 27 Feb 2017
    7.5
    High

    CVE-2017-5925

    Last Modified: 20 Apr 2025

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

    Published: 27 Feb 2017
    7.5
    High

    CVE-2017-5926

    Last Modified: 20 Apr 2025

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

    Published: 27 Feb 2017
    8.1
    High

    CVE-2017-2590

    Last Modified: 21 Nov 2024

    A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with certificate issuance, OCSP signing, and deletion of secret keys.

    Published: 27 Feb 2017
    4.9
    Medium

    CVE-2017-2632

    Last Modified: 21 Nov 2024

    A logic error in valid_role() in CloudForms role validation before 5.7.1.3 could allow a tenant administrator to create groups with a higher privilege level than the tenant administrator should have. This would allow an attacker with tenant administration access to elevate privileges.

    Published: 27 Feb 2017
    7.8
    High

    CVE-2017-8065

    Last Modified: 20 Apr 2025

    crypto/ccm.c in the Linux kernel 4.9.x and 4.10.x through 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 27 Feb 2017
    8.1
    High

    CVE-2017-0037

    Last Modified: 22 Apr 2026

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

    Published: 26 Feb 2017
    7.8
    High

    CVE-2017-6827

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6832

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    7.8
    High

    CVE-2017-6828

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6829

    Last Modified: 20 Apr 2025

    The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6830

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the alaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6834

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6835

    Last Modified: 20 Apr 2025

    The reset1 function in libaudiofile/modules/BlockCodec.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6836

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6837

    Last Modified: 20 Apr 2025

    WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large number of coefficients.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6838

    Last Modified: 20 Apr 2025

    Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6833

    Last Modified: 20 Apr 2025

    The runPull function in libaudiofile/modules/BlockCodec.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6839

    Last Modified: 20 Apr 2025

    Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    5.5
    Medium

    CVE-2017-6831

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 26 Feb 2017
    8.8
    High

    CVE-2017-2789

    Last Modified: 20 Apr 2025

    When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values are larger than the size of the buffer, the application will choose the smaller of the two and trust it to copy data from the file. This value is larger than the buffer size, which leads to a heap-based buffer overflow. This overflow corrupts an offset in the heap used in pointer arithmetic for writing data and can lead to code execution under the context of the application.

    Published: 24 Feb 2017
    7.5
    High

    CVE-2017-2791

    Last Modified: 20 Apr 2025

    JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint file. Due to the application incorrectly handling the error case for a function's result, the application will use this result in a pointer calculation for reading file data into. Due to this, the application will read data from the file into an invalid address thus corrupting memory. Under the right conditions, this can lead to code execution under the context of the application.

    Published: 24 Feb 2017
    8.8
    High

    CVE-2017-2790

    Last Modified: 20 Apr 2025

    When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy. This results in a heap-based buffer overflow and can lead to code execution under the context of the application.

    Published: 24 Feb 2017
    7.3
    High

    CVE-2016-4041

    Last Modified: 20 Apr 2025

    Plone 4.0 through 5.1a1 does not have security declarations for Dexterity content-related WebDAV requests, which allows remote attackers to gain webdav access via unspecified vectors.

    Published: 24 Feb 2017
    5.3
    Medium

    CVE-2016-4042

    Last Modified: 20 Apr 2025

    Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.

    Published: 24 Feb 2017
    4.9
    Medium

    CVE-2016-4043

    Last Modified: 20 Apr 2025

    Chameleon (five.pt) in Plone 5.0rc1 through 5.1a1 allows remote authenticated users to bypass Restricted Python by leveraging permissions to create or edit templates.

    Published: 24 Feb 2017
    8.8
    High

    CVE-2016-9975

    Last Modified: 20 Apr 2025

    IBM Jazz for Service Management 1.1.2.1 and 1.1.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1998714.

    Published: 24 Feb 2017
    7.2
    High

    CVE-2016-8998

    Last Modified: 20 Apr 2025

    IBM Tivoli Storage Manager Server 7.1 could allow an authenticated user with TSM administrator privileges to cause a buffer overflow using a specially crafted SQL query and execute arbitrary code on the server. IBM Reference #: 1998747.

    Published: 24 Feb 2017
    3.1
    Low

    CVE-2016-9009

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user with authority to create a cluster object to cause a denial of service to MQ clustering. IBM Reference #: 1998647.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6304

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6305

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6307

    Last Modified: 20 Apr 2025

    An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6310

    Last Modified: 20 Apr 2025

    An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6303

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "6 of 9. Invalid Write and Integer Overflow."

    Published: 24 Feb 2017
    5.5
    Medium

    CVE-2017-6197

    Last Modified: 20 Apr 2025

    The r_read_* functions in libr/include/r_endian.h in radare2 1.2.1 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by the r_read_le32 function.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6298

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "1 of 9. Null Pointer Deref / calloc return value not checked."

    Published: 24 Feb 2017
    5.5
    Medium

    CVE-2017-6299

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in lib/ytnef.c."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6300

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6301

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6302

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "5 of 9. Integer Overflow."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6306

    Last Modified: 20 Apr 2025

    An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6308

    Last Modified: 20 Apr 2025

    An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-6309

    Last Modified: 20 Apr 2025

    An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.

    Published: 24 Feb 2017
    7.4
    High

    CVE-2017-5643

    Last Modified: 20 Apr 2025

    Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE.

    Published: 24 Feb 2017
    5
    Medium

    CVE-2017-6437

    Last Modified: 20 Apr 2025

    The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

    Published: 24 Feb 2017
    7.3
    High

    CVE-2017-6438

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

    Published: 24 Feb 2017
    5
    Medium

    CVE-2017-6440

    Last Modified: 20 Apr 2025

    The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

    Published: 24 Feb 2017