CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2017-2634

    Last Modified: 21 Nov 2024

    It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A remote attacker could use this flaw to crash the system.

    Published: 24 Feb 2017
    7.8
    High

    CVE-2017-8066

    Last Modified: 20 Apr 2025

    drivers/net/can/usb/gs_usb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.2 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 24 Feb 2017
    6.1
    Medium

    CVE-2017-6099

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.

    Published: 23 Feb 2017
    6.1
    Medium

    CVE-2014-9916

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Bilboplanet 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) tribe_name or (2) tags parameter in a tribes page request to user/ or the (3) user_id or (4) fullname parameter to signup.php.

    Published: 23 Feb 2017
    5.5
    Medium

    CVE-2017-6076

    Last Modified: 20 Apr 2025

    In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.

    Published: 23 Feb 2017
    7.5
    High

    CVE-2017-6100

    Last Modified: 20 Apr 2025

    tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.

    Published: 23 Feb 2017
    5.4
    Medium

    CVE-2016-6055

    Last Modified: 20 Apr 2025

    IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1995515.

    Published: 23 Feb 2017
    6.1
    Medium

    CVE-2016-5883

    Last Modified: 20 Apr 2025

    IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1997010.

    Published: 23 Feb 2017
    8.1
    High

    CVE-2016-8974

    Last Modified: 20 Apr 2025

    IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997798.

    Published: 23 Feb 2017
    Unknown

    CVE-2017-6207

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-9578. Reason: This candidate is a reservation duplicate of CVE-2016-9578. Notes: All CVE users should reference CVE-2016-9578 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Feb 2017
    9.8
    Critical

    CVE-2017-6205

    Last Modified: 20 Apr 2025

    D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Command Bypass attacks via unspecified vectors.

    Published: 23 Feb 2017
    7.5
    High

    CVE-2017-6206

    Last Modified: 20 Apr 2025

    D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors.

    Published: 23 Feb 2017
    7.8
    High

    CVE-2017-18255

    Last Modified: 21 Nov 2024

    The perf_cpu_time_max_percent_handler function in kernel/events/core.c in the Linux kernel before 4.11 allows local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation.

    Published: 23 Feb 2017
    5.5
    Medium

    CVE-2017-6335

    Last Modified: 20 Apr 2025

    The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.

    Published: 23 Feb 2017
    7.5
    High

    CVE-2017-7186

    Last Modified: 20 Apr 2025

    libpcre1 in PCRE 8.40 and libpcre2 in PCRE2 10.23 allow remote attackers to cause a denial of service (segmentation violation for read access, and application crash) by triggering an invalid Unicode property lookup.

    Published: 23 Feb 2017
    5.5
    Medium

    CVE-2017-6353

    Last Modified: 20 Apr 2025

    net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.

    Published: 23 Feb 2017
    9.8
    Critical

    CVE-2017-6077

    Last Modified: 21 Apr 2026

    ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

    Published: 22 Feb 2017
    9.8
    Critical

    CVE-2017-6187

    Last Modified: 20 Apr 2025

    Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8547

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8551

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8553

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8548

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8552

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8554

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8555

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8558

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8559

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8560

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8536

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8537

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8538

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8539

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8540

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8541

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8543

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8544

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8545

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8546

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8549

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8556

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    Unknown

    CVE-2016-8557

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 22 Feb 2017
    6.5
    Medium

    CVE-2016-8915

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.

    Published: 22 Feb 2017
    6.5
    Medium

    CVE-2016-3013

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user to crash the MQ channel due to improper data conversion handling. IBM Reference #: 1998661.

    Published: 22 Feb 2017
    5.9
    Medium

    CVE-2016-3052

    Last Modified: 20 Apr 2025

    Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man in the middle techniques.

    Published: 22 Feb 2017
    6.5
    Medium

    CVE-2016-8986

    Last Modified: 20 Apr 2025

    IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.

    Published: 22 Feb 2017
    5.5
    Medium

    CVE-2017-6188

    Last Modified: 20 Apr 2025

    Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

    Published: 22 Feb 2017
    6.1
    Medium

    CVE-2016-9909

    Last Modified: 20 Apr 2025

    The serializer in html5lib before 0.99999999 might allow remote attackers to conduct cross-site scripting (XSS) attacks by leveraging mishandling of the < (less than) character in attribute values.

    Published: 22 Feb 2017
    7.5
    High

    CVE-2016-9956

    Last Modified: 20 Apr 2025

    The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

    Published: 22 Feb 2017