CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-2954

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2957

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to collaboration functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2958

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2959

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to parsing of color profile metadata. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2960

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to parsing of EXIF metadata. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2963

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to handling of the color profile in a TIFF file. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2964

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to the parsing of JPEG EXIF metadata. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2965

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to TIFF file parsing. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2966

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the image conversion engine related to parsing malformed TIFF segments. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2944

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when parsing crafted TIFF image files. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2949

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability in the XSLT engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2950

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to layout functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2955

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2956

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the JavaScript engine, related to manipulation of the navigation pane. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2961

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to validation functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2962

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable type confusion vulnerability in the XSLT engine related to localization functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-9147

    Last Modified: 20 Apr 2025

    named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.

    Published: 11 Jan 2017
    6.4
    Medium

    CVE-2016-9962

    Last Modified: 20 Apr 2025

    RunC allowed additional container processes via 'runc exec' to be ptraced by the pid 1 of the container. This allows the main processes of the container, if running as root, to gain access to file-descriptors of these new processes during the initialization and can lead to container escapes or modification of runC state before the process is fully placed inside the container.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-9444

    Last Modified: 20 Apr 2025

    named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2017-5507

    Last Modified: 20 Apr 2025

    Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a denial of service (memory consumption) via vectors involving a pixel cache.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-7592

    Last Modified: 20 Apr 2025

    The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.

    Published: 11 Jan 2017
    7.1
    High

    CVE-2017-2584

    Last Modified: 20 Apr 2025

    arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of service (use-after-free) via a crafted application that leverages instruction emulation for fxrstor, fxsave, sgdt, and sidt.

    Published: 11 Jan 2017
    6.5
    Medium

    CVE-2017-5525

    Last Modified: 20 Apr 2025

    Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

    Published: 11 Jan 2017
    6.5
    Medium

    CVE-2017-5526

    Last Modified: 20 Apr 2025

    Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-5546

    Last Modified: 20 Apr 2025

    The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to cause a denial of service (duplicate freelist entries and system crash) or possibly have unspecified other impact in opportunistic circumstances by leveraging the selection of a large value for a random number.

    Published: 11 Jan 2017
    5.5
    Medium

    CVE-2017-7594

    Last Modified: 20 Apr 2025

    The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-9131

    Last Modified: 20 Apr 2025

    named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-9778

    Last Modified: 21 Nov 2024

    An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.

    Published: 11 Jan 2017
    6.5
    Medium

    CVE-2017-5579

    Last Modified: 20 Apr 2025

    Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

    Published: 11 Jan 2017
    5.5
    Medium

    CVE-2017-7593

    Last Modified: 20 Apr 2025

    tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.

    Published: 11 Jan 2017
    8.8
    High

    CVE-2017-0002

    Last Modified: 20 Apr 2025

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via vectors involving the about:blank URL and data: URLs, aka "Microsoft Edge Elevation of Privilege Vulnerability."

    Published: 10 Jan 2017
    7.8
    High

    CVE-2017-0003

    Last Modified: 20 Apr 2025

    Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 10 Jan 2017
    7.5
    High

    CVE-2017-0004

    Last Modified: 20 Apr 2025

    The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."

    Published: 10 Jan 2017
    Unknown

    CVE-2016-6091

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-1897, CVE-2015-0119. Reason: This candidate is a duplicate of CVE-2015-1897 and CVE-2015-0119. Notes: All CVE users should reference CVE-2015-1897 and/or CVE-2015-0119 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Jan 2017
    5.9
    Medium

    CVE-2016-9247

    Last Modified: 20 Apr 2025

    Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence of packets may cause the Traffic Management Microkernel (TMM) to restart.

    Published: 10 Jan 2017
    9.8
    Critical

    CVE-2015-4594

    Last Modified: 20 Apr 2025

    eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

    Published: 10 Jan 2017
    7.5
    High

    CVE-2016-6287

    Last Modified: 20 Apr 2025

    The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.

    Published: 10 Jan 2017
    7.5
    High

    CVE-2016-6580

    Last Modified: 20 Apr 2025

    A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having that peer assign priority information for every possible HTTP/2 stream ID. The priority tree would happily continue to store the priority information for each stream, and would therefore allocate unbounded amounts of memory. Attempting to actually use a tree like this would also cause extremely high CPU usage to maintain the tree.

    Published: 10 Jan 2017
    6.1
    Medium

    CVE-2015-4591

    Last Modified: 20 Apr 2025

    eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.

    Published: 10 Jan 2017
    8.8
    High

    CVE-2015-4592

    Last Modified: 20 Apr 2025

    eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.

    Published: 10 Jan 2017
    8.8
    High

    CVE-2015-4593

    Last Modified: 20 Apr 2025

    eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the creation, modification and deletion of users, appointments and employees.

    Published: 10 Jan 2017
    9.8
    Critical

    CVE-2016-6830

    Last Modified: 20 Apr 2025

    The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).

    Published: 10 Jan 2017
    7.5
    High

    CVE-2016-6831

    Last Modified: 20 Apr 2025

    The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).

    Published: 10 Jan 2017
    6.1
    Medium

    CVE-2016-6837

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in MantisBT Filter API in MantisBT versions before 1.2.19, and versions 2.0.0-beta1, 1.3.0-beta1 allows remote attackers to inject arbitrary web script or HTML via the 'view_type' parameter.

    Published: 10 Jan 2017
    7.5
    High

    CVE-2016-6286

    Last Modified: 20 Apr 2025

    The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a "httpoxy" attack). This affects all versions of spiffy-cgi-handlers before 0.5.

    Published: 10 Jan 2017
    7.5
    High

    CVE-2016-6581

    Last Modified: 20 Apr 2025

    A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attack, specifically a so-called "HPACK Bomb" attack. This attack occurs when an attacker inserts a header field that is exactly the size of the HPACK dynamic header table into the dynamic header table. The attacker can then send a header block that is simply repeated requests to expand that field in the dynamic table. This can lead to a gigantic compression ratio of 4,096 or better, meaning that 16kB of data can decompress to 64MB of data on the target machine.

    Published: 10 Jan 2017
    9.8
    Critical

    CVE-2016-10126

    Last Modified: 20 Apr 2025

    Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.

    Published: 10 Jan 2017
    4.6
    Medium

    CVE-2016-7060

    Last Modified: 20 Apr 2025

    The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.

    Published: 10 Jan 2017
    9
    Critical

    CVE-2016-10127

    Last Modified: 20 Apr 2025

    PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

    Published: 10 Jan 2017
    8.8
    High

    CVE-2017-2925

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability in the JPEG XR codec. Successful exploitation could lead to arbitrary code execution.

    Published: 10 Jan 2017