CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2016-8944

    Last Modified: 20 Apr 2025

    IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV91456, IV90234.

    Published: 15 Feb 2017
    5.4
    Medium

    CVE-2016-8968

    Last Modified: 20 Apr 2025

    IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998515.

    Published: 15 Feb 2017
    7.8
    High

    CVE-2016-8972

    Last Modified: 20 Apr 2025

    IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

    Published: 15 Feb 2017
    6.1
    Medium

    CVE-2016-9010

    Last Modified: 20 Apr 2025

    IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM Reference #: 1997906.

    Published: 15 Feb 2017
    8.2
    High

    CVE-2017-5992

    Last Modified: 20 Apr 2025

    Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-5997

    Last Modified: 20 Apr 2025

    The SAP Message Server HTTP daemon in SAP KERNEL 7.21-7.49 allows remote attackers to cause a denial of service (memory consumption and process crash) via multiple msgserver/group?group= requests with a crafted size of the group parameter, aka SAP Security Note 2358972.

    Published: 15 Feb 2017
    9.1
    Critical

    CVE-2016-9706

    Last Modified: 20 Apr 2025

    IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1997918.

    Published: 15 Feb 2017
    7.8
    High

    CVE-2016-1883

    Last Modified: 20 Apr 2025

    The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2015-8979

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a long string sent to TCP port 4242.

    Published: 15 Feb 2017
    7.8
    High

    CVE-2016-1880

    Last Modified: 20 Apr 2025

    The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."

    Published: 15 Feb 2017
    7.8
    High

    CVE-2016-1881

    Last Modified: 20 Apr 2025

    The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2016-1888

    Last Modified: 20 Apr 2025

    The telnetd service in FreeBSD 9.3, 10.1, 10.2, 10.3, and 11.0 allows remote attackers to inject arguments to login and bypass authentication via vectors involving a "sequence of memory allocation failures."

    Published: 15 Feb 2017
    7.8
    High

    CVE-2016-1889

    Last Modified: 20 Apr 2025

    Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2980

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2981

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2977

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2978

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2974

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2975

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2976

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    6.1
    Medium

    CVE-2017-2969

    Last Modified: 20 Apr 2025

    Adobe Campaign versions 16.4 Build 8724 and earlier have a cross-site scripting (XSS) vulnerability.

    Published: 15 Feb 2017
    9.8
    Critical

    CVE-2017-2973

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 15 Feb 2017
    6.1
    Medium

    CVE-2017-5990

    Last Modified: 20 Apr 2025

    An issue was discovered in PhreeBooksERP before 2017-02-13. The vulnerability exists due to insufficient filtration of user-supplied data in the "form" HTTP GET parameter passed to the "PhreeBooksERP-master/extensions/ShippingMethods/ups/label_mgr/js_include.php" and "PhreeBooksERP-master/extensions/ShippingMethods/yrc/label_mgr/js_include.php" URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. NOTE: these js_include.php files do not exist in the SourceForge "stable release" (aka R37RC1).

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-5991

    Last Modified: 20 Apr 2025

    An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.

    Published: 15 Feb 2017
    9.1
    Critical

    CVE-2017-2968

    Last Modified: 20 Apr 2025

    Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-2979

    Last Modified: 20 Apr 2025

    Adobe Digital Editions versions 4.5.3 and earlier have an exploitable buffer over-read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 15 Feb 2017
    8.8
    High

    CVE-2017-2994

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in Primetime SDK event dispatch. Successful exploitation could lead to arbitrary code execution.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-12934

    Last Modified: 20 Apr 2025

    ext/standard/var_unserializer.re in PHP 7.0.x before 7.0.21 and 7.1.x before 7.1.7 is prone to a heap use after free while unserializing untrusted data, related to the zval_get_type function in Zend/zend_types.h. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

    Published: 15 Feb 2017
    7.5
    High

    CVE-2017-3163

    Last Modified: 20 Apr 2025

    When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file name. However, Solr before 5.5.4 and 6.x before 6.4.1 did not validate the file name, hence it was possible to craft a special request involving path traversal, leaving any file readable to the Solr server process exposed. Solr servers protected and restricted by firewall rules and/or authentication would not be at risk since only trusted clients and users would gain direct HTTP access.

    Published: 15 Feb 2017
    7.8
    High

    CVE-2017-8062

    Last Modified: 20 Apr 2025

    drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 15 Feb 2017
    5.5
    Medium

    CVE-2017-14431

    Last Modified: 20 Apr 2025

    Memory leak in Xen 3.3 through 4.8.x allows guest OS users to cause a denial of service (ARM or x86 AMD host OS memory consumption) by continually rebooting, because certain cleanup is skipped if no pass-through device was ever assigned, aka XSA-207.

    Published: 15 Feb 2017
    5.9
    Medium

    CVE-2017-2622

    Last Modified: 21 Nov 2024

    An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

    Published: 15 Feb 2017
    9.8
    Critical

    CVE-2017-18922

    Last Modified: 21 Nov 2024

    It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.

    Published: 15 Feb 2017
    5.5
    Medium

    CVE-2017-2621

    Last Modified: 21 Nov 2024

    An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

    Published: 15 Feb 2017
    5.4
    Medium

    CVE-2016-10223

    Last Modified: 20 Apr 2025

    An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2988

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    9.1
    Critical

    CVE-2017-6969

    Last Modified: 20 Apr 2025

    readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2985

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2987

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable integer overflow vulnerability related to Flash Broker COM. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2990

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in the h264 decompression routine. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2991

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in the h264 codec (related to decompression). Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2992

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2993

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability related to event handlers. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2996

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability in Primetime SDK. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    7.5
    High

    CVE-2017-6004

    Last Modified: 20 Apr 2025

    The compile_bracket_matchingpath function in pcre_jit_compile.c in PCRE through 8.x before revision 1680 (e.g., the PHP 7.1.1 bundled version) allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted regular expression.

    Published: 14 Feb 2017
    5.5
    Medium

    CVE-2017-7210

    Last Modified: 20 Apr 2025

    objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash.

    Published: 14 Feb 2017
    8.2
    High

    CVE-2017-2627

    Last Modified: 21 Nov 2024

    A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that have wildcards that allow directory traversal with '..' and it grants full passwordless root access to the validations user.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2982

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in a routine related to player shutdown. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2984

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the h264 decoder routine. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017
    8.8
    High

    CVE-2017-2986

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.

    Published: 14 Feb 2017