CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2017-5141

    Last Modified: 20 Apr 2025

    An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. An attacker can establish a new user session, without invalidating any existing session identifier, which gives the opportunity to steal authenticated sessions (SESSION FIXATION).

    Published: 13 Feb 2017
    10
    Critical

    CVE-2017-5145

    Last Modified: 20 Apr 2025

    An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.

    Published: 13 Feb 2017
    7.8
    High

    CVE-2017-5153

    Last Modified: 20 Apr 2025

    An issue was discovered in OSIsoft PI Coresight 2016 R2 and earlier versions, and PI Web API 2016 R2 when deployed using the PI AF Services 2016 R2 integrated install kit. An information exposure through server log files vulnerability has been identified, which may allow service account passwords to become exposed for the affected services, potentially leading to unauthorized shutdown of the affected PI services as well as potential reuse of domain credentials.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2017-5154

    Last Modified: 20 Apr 2025

    An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the application and its data files.

    Published: 13 Feb 2017
    7.3
    High

    CVE-2017-5155

    Last Modified: 20 Apr 2025

    An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be compromised as well.

    Published: 13 Feb 2017
    6.1
    Medium

    CVE-2014-9760

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2015-8768

    Last Modified: 20 Apr 2025

    click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2015-8771

    Last Modified: 20 Apr 2025

    The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2016-10026

    Last Modified: 20 Apr 2025

    ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, which allows remote attackers to revert certain changes by leveraging permissions to change the page before the revision was made.

    Published: 13 Feb 2017
    5.3
    Medium

    CVE-2016-2787

    Last Modified: 20 Apr 2025

    The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.

    Published: 13 Feb 2017
    5.5
    Medium

    CVE-2016-4546

    Last Modified: 20 Apr 2025

    Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2016-4547

    Last Modified: 20 Apr 2025

    Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2016-5100

    Last Modified: 20 Apr 2025

    Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attackers to guess the password reset token by predicting a value.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2016-7565

    Last Modified: 20 Apr 2025

    install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.

    Published: 13 Feb 2017
    7
    High

    CVE-2016-8659

    Last Modified: 20 Apr 2025

    Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2016-8859

    Last Modified: 20 Apr 2025

    Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2016-3995

    Last Modified: 20 Apr 2025

    The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks.

    Published: 13 Feb 2017
    5.9
    Medium

    CVE-2017-3896

    Last Modified: 20 Apr 2025

    Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.

    Published: 13 Feb 2017
    5.4
    Medium

    CVE-2017-3902

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web user interface (UI) in Intel Security ePO 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows authenticated users to inject malicious Java scripts via bypassing input validation.

    Published: 13 Feb 2017
    7.4
    High

    CVE-2016-8495

    Last Modified: 20 Apr 2025

    An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 allows remote attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack via the Fortisandbox devices probing feature.

    Published: 13 Feb 2017
    7.8
    High

    CVE-2017-6345

    Last Modified: 20 Apr 2025

    The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local users to cause a denial of service (BUG_ON) or possibly have unspecified other impact via crafted system calls.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2017-7401

    Last Modified: 20 Apr 2025

    Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.

    Published: 13 Feb 2017
    5.5
    Medium

    CVE-2017-5973

    Last Modified: 20 Apr 2025

    The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors related to control transfer descriptor sequence.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2017-6349

    Last Modified: 20 Apr 2025

    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

    Published: 13 Feb 2017
    9.8
    Critical

    CVE-2017-6350

    Last Modified: 20 Apr 2025

    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

    Published: 13 Feb 2017
    5.5
    Medium

    CVE-2017-6965

    Last Modified: 20 Apr 2025

    readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

    Published: 13 Feb 2017
    5.5
    Medium

    CVE-2017-6966

    Last Modified: 20 Apr 2025

    readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

    Published: 13 Feb 2017
    5.5
    Medium

    CVE-2017-7209

    Last Modified: 20 Apr 2025

    The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.

    Published: 13 Feb 2017
    6.1
    Medium

    CVE-2017-7463

    Last Modified: 21 Nov 2024

    JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a reflected XSS via artifact upload. A malformed XML file, if uploaded, causes an error message to appear that includes part of the bad XML code verbatim without filtering out scripts. Successful exploitation would allow execution of script code within the context of the affected user.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2017-7867

    Last Modified: 20 Apr 2025

    International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function.

    Published: 13 Feb 2017
    7.5
    High

    CVE-2017-7868

    Last Modified: 20 Apr 2025

    International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function.

    Published: 13 Feb 2017
    6.1
    Medium

    CVE-2017-5962

    Last Modified: 20 Apr 2025

    An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the "force_ua" HTTP GET parameter passed to the "/contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Feb 2017
    6.1
    Medium

    CVE-2017-5960

    Last Modified: 20 Apr 2025

    An issue was discovered in Phalcon Eye through 0.4.1. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "phalconeye-master/public/external/pydio/plugins/editor.webodf/frame.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Feb 2017
    6.1
    Medium

    CVE-2017-5961

    Last Modified: 20 Apr 2025

    An issue was discovered in ionize through 1.0.8. The vulnerability exists due to insufficient filtration of user-supplied data in the "path" HTTP GET parameter passed to the "ionize-master/themes/admin/javascript/tinymce/jscripts/tiny_mce/plugins/codemirror/dialog.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Feb 2017
    6.1
    Medium

    CVE-2017-5964

    Last Modified: 20 Apr 2025

    An issue was discovered in Emoncms through 9.8.0. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "emoncms-master/Modules/vis/visualisations/compare.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Feb 2017
    6.1
    Medium

    CVE-2017-5963

    Last Modified: 20 Apr 2025

    An issue was discovered in caddy (for TYPO3) before 7.2.10. The vulnerability exists due to insufficient filtration of user-supplied data in the "paymillToken" HTTP POST parameter passed to the "caddy/Resources/Public/JavaScript/e-payment/paymill/api/php/payment.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 12 Feb 2017
    7.5
    High

    CVE-2017-5972

    Last Modified: 20 Apr 2025

    The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship between the GitHub Engineering finding and the Trigemini.c attack code.

    Published: 12 Feb 2017
    7.8
    High

    CVE-2017-8061

    Last Modified: 20 Apr 2025

    drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 12 Feb 2017
    7.5
    High

    CVE-2017-6497

    Last Modified: 20 Apr 2025

    An issue was discovered in ImageMagick 6.9.7. A specially crafted psd file could lead to a NULL pointer dereference (thus, a DoS).

    Published: 11 Feb 2017
    7.8
    High

    CVE-2016-8711

    Last Modified: 20 Apr 2025

    A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this vulnerability.

    Published: 10 Feb 2017
    7.8
    High

    CVE-2016-8709

    Last Modified: 20 Apr 2025

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.

    Published: 10 Feb 2017
    7.8
    High

    CVE-2016-8713

    Last Modified: 20 Apr 2025

    A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.

    Published: 10 Feb 2017
    6.1
    Medium

    CVE-2016-10215

    Last Modified: 20 Apr 2025

    An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP POST parameters passed to a "site/index.php/../../extensions/com.fastspot.form-builder/ajax/redraw-field.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 10 Feb 2017
    6.1
    Medium

    CVE-2016-10216

    Last Modified: 20 Apr 2025

    An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtration of user-supplied data in the "value" HTTP POST parameter passed to the "itdb-1.23/js/DataTables-1.8.2/examples/examples_support/editable_ajax.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 10 Feb 2017
    6.1
    Medium

    CVE-2017-5942

    Last Modified: 20 Apr 2025

    An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.

    Published: 10 Feb 2017
    9.8
    Critical

    CVE-2017-5954

    Last Modified: 20 Apr 2025

    An issue was discovered in the serialize-to-js package 0.5.0 for Node.js. Untrusted data passed into the deserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

    Published: 10 Feb 2017
    6.1
    Medium

    CVE-2017-5945

    Last Modified: 20 Apr 2025

    An issue was discovered in the PoodLL Filter plugin through 3.0.20 for Moodle. The vulnerability exists due to insufficient filtration of user-supplied data in the "poodll_audio_url" HTTP GET parameter passed to the "filter_poodll_moodle32_2016112802/poodll/mp3recorderskins/brazil/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

    Published: 10 Feb 2017
    6.1
    Medium

    CVE-2017-2674

    Last Modified: 21 Nov 2024

    JBoss BRMS 6 and BPM Suite 6 before 6.4.3 are vulnerable to a stored XSS via several lists in Business Central. The flaw is due to lack of sanitation of user input when creating new lists. Remote, authenticated attackers that have privileges to create lists can store scripts in them, which are not properly sanitized before showing to other users, including admins.

    Published: 10 Feb 2017
    5.6
    Medium

    CVE-2017-9310

    Last Modified: 20 Apr 2025

    QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) outside the allocated descriptor buffer.

    Published: 10 Feb 2017
    8.1
    High

    CVE-2017-1000034

    Last Modified: 20 Apr 2025

    Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.

    Published: 10 Feb 2017