CVE Feed

    Dashboard / CVE

    4.5
    Medium

    CVE-2017-2580

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.

    Published: 5 Feb 2017
    3.3
    Low

    CVE-2017-2579

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the application to crash or possibly allows code execution.

    Published: 5 Feb 2017
    7.5
    High

    CVE-2017-6311

    Last Modified: 20 Apr 2025

    gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message.

    Published: 5 Feb 2017
    4.5
    Medium

    CVE-2017-2581

    Last Modified: 21 Nov 2024

    An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.

    Published: 5 Feb 2017
    7.8
    High

    CVE-2017-8063

    Last Modified: 20 Apr 2025

    drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 5 Feb 2017
    9.8
    Critical

    CVE-2017-5897

    Last Modified: 20 Apr 2025

    The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.

    Published: 5 Feb 2017
    Unknown

    CVE-2016-0730

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 4 Feb 2017
    Unknown

    CVE-2015-0229

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2015. Notes: none

    Published: 4 Feb 2017
    Unknown

    CVE-2016-8753

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2016. Notes: none

    Published: 4 Feb 2017
    6.1
    Medium

    CVE-2017-5882

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 4 Feb 2017
    6.5
    Medium

    CVE-2017-5880

    Last Modified: 20 Apr 2025

    Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Light versions before 6.5.2 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request, aka SPL-130279.

    Published: 4 Feb 2017
    6.1
    Medium

    CVE-2016-7147

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, as demonstrated by the obj_ids:tokens parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-7140.

    Published: 4 Feb 2017
    7.5
    High

    CVE-2017-5970

    Last Modified: 20 Apr 2025

    The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.

    Published: 4 Feb 2017
    7.6
    High

    CVE-2017-2617

    Last Modified: 5 Aug 2025

    hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where hawtio is deployed.

    Published: 4 Feb 2017
    7.8
    High

    CVE-2017-8068

    Last Modified: 20 Apr 2025

    drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 4 Feb 2017
    7.8
    High

    CVE-2017-8069

    Last Modified: 20 Apr 2025

    drivers/net/usb/rtl8150.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 4 Feb 2017
    7.8
    High

    CVE-2017-8070

    Last Modified: 20 Apr 2025

    drivers/net/usb/catc.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 4 Feb 2017
    9.8
    Critical

    CVE-2017-5946

    Last Modified: 20 Apr 2025

    The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

    Published: 4 Feb 2017
    6.8
    Medium

    CVE-2015-4049

    Last Modified: 20 Apr 2025

    Unisys Libra 43xx, 63xx, and 83xx, and FS600 class systems with MCP-FIRMWARE 40.0 before 40.0IC4 Build 270 might allow remote authenticated users to cause a denial of service (data corruption or system crash) via vectors related to using program operators during EPSILON (level 5) based codefiles at peak memory usage, which triggers CPM stack corruption.

    Published: 3 Feb 2017
    8.1
    High

    CVE-2016-6500

    Last Modified: 20 Apr 2025

    Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor with returnObjFlag set to true, which allows remote attackers to execute arbitrary code via a crafted serialized Java object, aka LDAP entry poisoning.

    Published: 3 Feb 2017
    6.5
    Medium

    CVE-2016-6188

    Last Modified: 20 Apr 2025

    Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large attachment, related to temporary files.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-8568

    Last Modified: 20 Apr 2025

    The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-5115

    Last Modified: 20 Apr 2025

    The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-2317

    Last Modified: 20 Apr 2025

    Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-2318

    Last Modified: 20 Apr 2025

    GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-4352

    Last Modified: 20 Apr 2025

    Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-4570

    Last Modified: 20 Apr 2025

    The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-4571

    Last Modified: 20 Apr 2025

    The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-5241

    Last Modified: 20 Apr 2025

    magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.

    Published: 3 Feb 2017
    7.5
    High

    CVE-2016-9108

    Last Modified: 20 Apr 2025

    Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-9642

    Last Modified: 20 Apr 2025

    JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

    Published: 3 Feb 2017
    5.5
    Medium

    CVE-2016-8569

    Last Modified: 20 Apr 2025

    The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.

    Published: 3 Feb 2017
    5.3
    Medium

    CVE-2017-3822

    Last Modified: 11 Aug 2026

    A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, remote attacker to add arbitrary entries to the audit log. This vulnerability affects Cisco Firepower Threat Defense Software versions 6.1.x on the following vulnerable products that have enabled FDM: ASA5506-X ASA5506W-X ASA5506H-X ASA5508-X ASA5516-X ASA5512-X ASA5515-X ASA5525-X ASA5545-X ASA5555-X. More Information: CSCvb86860. Known Affected Releases: FRANGELICO. Known Fixed Releases: 6.2.0.

    Published: 3 Feb 2017
    5.3
    Medium

    CVE-2017-3806

    Last Modified: 11 Aug 2026

    A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the device. More Information: CSCvb61343. Known Affected Releases: 2.0(1.68). Known Fixed Releases: 2.0(1.118) 2.1(1.47) 92.1(1.1646) 92.1(1.1763) 92.2(1.101).

    Published: 3 Feb 2017
    7.5
    High

    CVE-2016-8211

    Last Modified: 20 Apr 2025

    EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    7.5
    High

    CVE-2016-8212

    Last Modified: 20 Apr 2025

    An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that the OCSP response is valid indefinitely instead of restricting its validity for a brief period surrounding the thisUpdate time. This vulnerability is similar to the issue described in CVE-2015-4748.

    Published: 3 Feb 2017
    7.2
    High

    CVE-2016-9871

    Last Modified: 20 Apr 2025

    EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected system.

    Published: 3 Feb 2017
    6.1
    Medium

    CVE-2016-9872

    Last Modified: 20 Apr 2025

    EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has Reflected Cross-Site Scripting Vulnerabilities that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    6.4
    Medium

    CVE-2016-0890

    Last Modified: 20 Apr 2025

    EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclosure vulnerability that may potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    6.1
    Medium

    CVE-2016-0919

    Last Modified: 20 Apr 2025

    EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    5.4
    Medium

    CVE-2017-3810

    Last Modified: 20 Apr 2025

    A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: 10.0_R2_tanggula.

    Published: 3 Feb 2017
    4.4
    Medium

    CVE-2016-6648

    Last Modified: 20 Apr 2025

    EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administrator with configuration privileges may access this sensitive system file and compromise the affected system.

    Published: 3 Feb 2017
    6.7
    Medium

    CVE-2016-6649

    Last Modified: 20 Apr 2025

    EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface and escalate his privileges to root.

    Published: 3 Feb 2017
    3.7
    Low

    CVE-2016-8217

    Last Modified: 20 Apr 2025

    EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current MAC one byte at a time. This is possible because Crypto-J uses a non-constant-time method to compare the stored MAC with the calculated MAC. This vulnerability is similar to the issue described in CVE-2015-2601.

    Published: 3 Feb 2017
    6.3
    Medium

    CVE-2016-9873

    Last Modified: 20 Apr 2025

    EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged attacker could potentially exploit this vulnerability to access information, modify data or disrupt services by causing execution of arbitrary DQL commands on the application.

    Published: 3 Feb 2017
    9.8
    Critical

    CVE-2017-2766

    Last Modified: 20 Apr 2025

    EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    9.8
    Critical

    CVE-2017-2767

    Last Modified: 20 Apr 2025

    EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains a Java RMI Remote Code Execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    9.8
    Critical

    CVE-2017-2768

    Last Modified: 20 Apr 2025

    EMC Network Configuration Manager (NCM) 9.3.x, EMC Network Configuration Manager (NCM) 9.4.0.x, EMC Network Configuration Manager (NCM) 9.4.1.x, EMC Network Configuration Manager (NCM) 9.4.2.x contains an Improper Authentication vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017
    5.8
    Medium

    CVE-2017-3809

    Last Modified: 20 Apr 2025

    A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Releases: 6.1.0 6.2.0. Known Fixed Releases: 6.1.0.1 6.2.0.

    Published: 3 Feb 2017
    6.7
    Medium

    CVE-2016-8216

    Last Modified: 20 Apr 2025

    EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.

    Published: 3 Feb 2017