8
    High

    CVE-2017-1000432

    Last Modified: 8 Jan 2018

    Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access

    Source:Anand Meyyappan
    Published:2 Jan 2018
    7
    High

    CVE-2017-1000409

    Last Modified: 8 Jan 2018

    A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

    Source:Qualys Corporation
    Published:11 Dec 2017
    7.8
    High

    CVE-2017-1000408

    Last Modified: 8 Jan 2018

    A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

    Source:Qualys Corporation
    Published:11 Dec 2017
    7
    High

    CVE-2017-1000405

    Last Modified: 19 Mar 2018

    The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.

    Source:Bindecy
    Published:30 Nov 2017
    7.8
    High

    CVE-2017-1000379

    Last Modified: 19 Jul 2017

    The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where the stack is mapped allowing attackers to more easily manipulate the stack. Linux Kernel version 4.11.5 is affected.

    Source:Qualys Corporation
    Published:19 Jun 2017
    9.8
    Critical

    CVE-2017-1000375

    Last Modified: 29 Jun 2017

    NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.

    Source:Qualys Corporation
    Published:19 Jun 2017
    6.5
    Medium

    CVE-2017-1000373

    Last Modified: 19 Jul 2017

    The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code execution attacks. This affects OpenBSD 6.1 and possibly earlier versions.

    Source:Qualys Corporation
    Published:19 Jun 2017
    7.8
    High

    CVE-2017-1000371

    Last Modified: 19 Jul 2017

    The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then the stack will be grown down to 0x80000000, and as the PIE binary is mapped above 0x80000000 the minimum distance between the end of the PIE binary's read-write segment and the start of the stack becomes small enough that the stack guard page can be jumped over by an attacker. This affects Linux Kernel version 4.11.5. This is a different issue than CVE-2017-1000370 and CVE-2017-1000365. This issue appears to be limited to i386 based systems.

    Source:Qualys Corporation
    Published:19 Jun 2017
    7.8
    High

    CVE-2017-1000370

    Last Modified: 19 Jul 2017

    The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nullifying the protection of the offset2lib patch. This affects Linux Kernel version 4.11.5 and earlier. This is a different issue than CVE-2017-1000371. This issue appears to be limited to i386 based systems.

    Source:Qualys Corporation
    Published:19 Jun 2017
    6.4
    Medium

    CVE-2017-1000367

    Last Modified: 20 Jun 2017

    Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.

    Source:Qualys Corporation
    Published:30 May 2017
    7.8
    High

    CVE-2017-1000366

    Last Modified: 19 Jul 2017

    glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.

    Source:Qualys Corporation
    Published:19 Jun 2017
    7.4
    High

    CVE-2017-1000364

    Last Modified: 16 Oct 2018

    An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stackguard page was introduced in 2010).

    Source:Metasploit
    Published:19 Jun 2017
    9.8
    Critical

    CVE-2017-1000353

    Last Modified: 5 May 2017

    Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers to transfer a serialized Java `SignedObject` object to the Jenkins CLI, that would be deserialized using a new `ObjectInputStream`, bypassing the existing blacklist-based protection mechanism. We're fixing this issue by adding `SignedObject` to the blacklist. We're also backporting the new HTTP CLI protocol from Jenkins 2.54 to LTS 2.46.2, and deprecating the remoting-based (i.e. Java serialization) CLI protocol, disabling it by default.

    Source:SecuriTeam
    Published:26 Apr 2017
    7.8
    High

    CVE-2017-1000253

    Last Modified: 8 Jan 2018

    Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.

    Source:Qualys Corporation
    Published:26 Sept 2017
    8
    High

    CVE-2017-1000251

    Last Modified: 22 Sept 2017

    The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

    Source:Marcin Kozlowski
    Published:12 Sept 2017
    6.5
    Medium

    CVE-2017-1000250

    Last Modified: 20 Apr 2025

    All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests.

    Published:12 Sept 2017
    5.9
    Medium

    CVE-2017-1000209

    Last Modified: 20 Apr 2025

    The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.

    Published:17 Nov 2017
    8.8
    High

    CVE-2017-1000208

    Last Modified: 20 Apr 2025

    A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

    Published:17 Nov 2017
    8.8
    High

    CVE-2017-1000207

    Last Modified: 20 Apr 2025

    A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a well-crafted yaml specification.

    Published:27 Nov 2017
    7.5
    High

    CVE-2017-1000170

    Last Modified: 22 Mar 2021

    jqueryFileTree 2.1.5 and older Directory Traversal

    Source:Nicholas Ferreira
    Published:17 Nov 2017
    7.2
    High

    CVE-2017-1000119

    Last Modified: 10 Sept 2019

    October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise and possibly other applications on the server.

    Source:Metasploit
    Published:4 Oct 2017
    8.8
    High

    CVE-2017-1000117

    Last Modified: 1 Sept 2017

    A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

    Source:Metasploit
    Published:10 Aug 2017
    7
    High

    CVE-2017-1000112

    Last Modified: 3 Aug 2018

    Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.

    Source:Metasploit
    Published:10 Aug 2017
    7.8
    High

    CVE-2017-1000083

    Last Modified: 11 Feb 2019

    backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.

    Source:Matlink
    Published:13 Jul 2017
    7.5
    High

    CVE-2017-1000028

    Last Modified: 17 Aug 2018

    Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.

    Source:Dhiraj Mishra
    Published:13 Jul 2017
    Low

    CVE-2017-1000000

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. This issue lacks details and cannot be determined if it is a security issue or not. Notes: none

    Published:19 Feb 2019
    Unknown

    CVE-2017-98505

    https://github.com/mike-williams/Struts2Vuln

    9.3
    Critical

    CVE-2017-20251

    Last Modified: 9 Jun 2026

    WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes through the WordPress REST API. Attackers can send POST requests to the wp-json/wp/v2/posts endpoint with crafted content containing insert_php shortcodes to include and execute remote PHP files on the server.

    Published:9 Jun 2026
    8.3
    High

    CVE-2017-20192

    Last Modified: 8 Apr 2026

    The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters submitted during form entries like 'after_html' in versions before 2.05.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

    Published:16 Oct 2024
    3.5
    Low

    CVE-2017-20165

    Last Modified: 21 Nov 2024

    A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to address this issue. The identifier of the patch is c38a0166c266a679c8de012d4eaccec3f944e685. It is recommended to upgrade the affected component. The identifier VDB-217665 was assigned to this vulnerability.

    Published:9 Jan 2023
    7.5
    High

    CVE-2017-18640

    Last Modified: 21 Nov 2024

    The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.

    Published:12 Dec 2019
    6.1
    Medium

    CVE-2017-18635

    Last Modified: 21 Nov 2024

    An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

    Published:12 Jan 2019
    7.2
    High

    CVE-2017-18486

    Last Modified: 21 Nov 2024

    Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.

    Published:9 Aug 2019
    6.5
    Medium

    CVE-2017-18357

    Last Modified: 23 May 2019

    Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of the Shopware_Controllers_Backend_ProductStream controller, with resultant XXE via instantiation of a SimpleXMLElement object.

    Source:Metasploit
    Published:15 Jan 2019
    9.8
    Critical

    CVE-2017-18349

    Last Modified: 21 Nov 2024

    parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.

    Published:23 Oct 2018
    9.8
    Critical

    CVE-2017-18345

    Last Modified: 21 Nov 2024

    The Joomanager component through 2.0.0 for Joomla! has an arbitrary file download issue, resulting in exposing the credentials of the database via an index.php?option=com_joomanager&controller=details&task=download&path=configuration.php request.

    Published:26 Aug 2018
    5.5
    Medium

    CVE-2017-18344

    Last Modified: 21 Nov 2024

    The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allows userspace applications to read arbitrary kernel memory (on a kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE).

    Published:15 Dec 2017
    6.5
    Medium

    CVE-2017-18256

    Last Modified: 17 Apr 2018

    Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript code, because window dialogs are mishandled.

    Source:Sahil Tikoo
    Published:4 Apr 2018
    5.3
    Medium

    CVE-2017-18195

    Last Modified: 20 Sept 2019

    An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enumerate comments from all blog posts by POSTing requests to /index.php/tools/required/conversations/view_ajax with incremental 'cnvID' integers.

    Source:Chapman Schleiss
    Published:26 Feb 2018
    7.8
    High

    CVE-2017-18078

    Last Modified: 31 Jan 2018

    systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

    Source:Michael Orlitzky
    Published:24 Dec 2017
    9.8
    Critical

    CVE-2017-18044

    Last Modified: 21 Nov 2024

    A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of this vulnerability does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon. This is a different vulnerability than CVE-2017-3195.

    Published:19 Jan 2018
    7.1
    High

    CVE-2017-18019

    Last Modified: 15 Feb 2018

    In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.

    Source:SecuriTeam
    Published:4 Jan 2018
    5.3
    Medium

    CVE-2017-18016

    Last Modified: 11 Jan 2018

    Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by requesting other websites via the Parity web proxy engine (reusing the current website's token, which is not bound to an origin).

    Source:tintinweb
    Published:11 Jan 2018
    9.8
    Critical

    CVE-2017-18001

    Last Modified: 15 Feb 2018

    Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

    Source:SecuriTeam
    Published:31 Dec 2017
    9.8
    Critical

    CVE-2017-17999

    Last Modified: 15 Jan 2018

    SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL commands via the search parameter to index.php/knowledge_base/get_article_suggestion/.

    Source:Ahmad Mahfouz
    Published:23 Jan 2018
    9.8
    Critical

    CVE-2017-17976

    Last Modified: 15 Jan 2018

    In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.

    Source:Ahmad Mahfouz
    Published:26 Jan 2018
    9.8
    Critical

    CVE-2017-17970

    Last Modified: 10 Jan 2018

    Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to login.php; the (2) season_id parameter to themes/flixer/ajax/load_season.php; the (3) movie_id parameter to themes/flixer/ajax/get_rating.php; the (4) rating or (5) movie_id parameter to themes/flixer/ajax/update_rating.php; or the (6) id parameter to themes/flixer/ajax/set_player_source.php.

    Source:Ahmad Mahfouz
    Published:12 Jan 2018
    9.8
    Critical

    CVE-2017-17968

    Last Modified: 11 Nov 2022

    A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.

    Source:Aloyce J. Makalanga
    Published:29 Dec 2017
    9.8
    Critical

    CVE-2017-17932

    Last Modified: 28 Dec 2017

    A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.

    Source:Aloyce J. Makalanga
    Published:28 Dec 2017
    8.1
    High

    CVE-2017-17917

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

    Published:29 Dec 2017