9.8
    Critical

    CVE-2017-17485

    Last Modified: 27 Aug 2025

    FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.

    Published:12 Dec 2017
    9.8
    Critical

    CVE-2017-17417

    Last Modified: 22 Feb 2019

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backup 11.3.0.12. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of NVBUPhaseStatus Acknowledge method requests. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the underlying database. Was ZDI-CAN-4228.

    Source:Chris Anastasio
    Published:8 Feb 2018
    9.8
    Critical

    CVE-2017-17411

    Last Modified: 4 Jan 2018

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in the lack of proper validation of user data before executing a system call. An attacker could leverage this vulnerability to execute code with root privileges. Was ZDI-CAN-4892.

    Source:Metasploit
    Published:21 Dec 2017
    8.8
    High

    CVE-2017-17405

    Last Modified: 21 Dec 2017

    Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.

    Source:Etienne Stalmans
    Published:14 Dec 2017
    7.5
    High

    CVE-2017-17309

    Last Modified: 21 Nov 2024

    Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received HTTP requests, a remote attacker may access the local files on the device without authentication.

    Published:14 Jun 2018
    Low

    CVE-2017-17275

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published:5 Mar 2019
    8.8
    High

    CVE-2017-17215

    Last Modified: 1 Jan 2018

    Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could send malicious packets to port 37215 to launch attacks. Successful exploit could lead to the remote execution of arbitrary code.

    Source:anonymous
    Published:20 Mar 2018
    9.8
    Critical

    CVE-2017-17111

    Last Modified: 6 Dec 2017

    Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.

    Source:Ihsan Sencan
    Published:11 Dec 2017
    9.8
    Critical

    CVE-2017-17110

    Last Modified: 6 Dec 2017

    Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.

    Source:Ihsan Sencan
    Published:11 Dec 2017
    7.8
    High

    CVE-2017-17099

    Last Modified: 20 Apr 2025

    There exists an unauthenticated SEH based Buffer Overflow vulnerability in the HTTP server of Flexense SyncBreeze Enterprise v10.1.16. When sending a GET request with an excessive length, it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows SYSTEM account.

    Published:3 Dec 2017
    9.8
    Critical

    CVE-2017-17098

    Last Modified: 5 Jan 2018

    The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.

    Source:Noman Riffat
    Published:2 Jan 2018
    9.8
    Critical

    CVE-2017-17097

    Last Modified: 5 Jan 2018

    gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

    Source:Noman Riffat
    Published:2 Jan 2018
    8.8
    High

    CVE-2017-17095

    Last Modified: 11 Dec 2017

    tools/pal2rgb.c in pal2rgb in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (TIFFSetupStrips heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file.

    Source:Jungun Baek
    Published:29 Nov 2017
    7.5
    High

    CVE-2017-17090

    Last Modified: 7 Feb 2018

    An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified Asterisk 13.13-cert7 and older. If the chan_skinny (aka SCCP protocol) channel driver is flooded with certain requests, it can cause the asterisk process to use excessive amounts of virtual memory, eventually causing asterisk to stop processing requests of any kind.

    Source:Juan Sacco
    Published:2 Dec 2017
    7.5
    High

    CVE-2017-17088

    Last Modified: 15 Dec 2017

    The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The web server does not check bounds when reading server requests in the Host header on making a connection, resulting in a classic Buffer Overflow that causes a Denial of Service.

    Source:Manuel García Cárdenas
    Published:19 Dec 2017
    7.5
    High

    CVE-2017-17085

    Last Modified: 8 Dec 2017

    In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

    Source:Wireshark
    Published:30 Nov 2017
    6.5
    Medium

    CVE-2017-17062

    Last Modified: 12 Jun 2018

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.

    Source:Open-Xchange
    Published:15 Jun 2018
    7.5
    High

    CVE-2017-17058

    Last Modified: 30 Nov 2017

    The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/woocommerce/templates/emails/plain/ URI, which accesses a parent directory. NOTE: a software maintainer indicates that Directory Traversal is not possible because all of the template files have "if (!defined('ABSPATH')) {exit;}" code

    Source:Fu2x2000
    Published:29 Nov 2017
    9
    Critical

    CVE-2017-17055

    Last Modified: 1 Dec 2017

    Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.

    Source:hyp3rlinx
    Published:6 Dec 2017
    8.8
    High

    CVE-2017-17020

    Last Modified: 4 Nov 2022

    On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DCS-5020L devices with firmware before 1.15.01, command injection in alphapd (binary responsible for running the camera's web server) allows remote authenticated attackers to execute code through sanitized /setSystemAdmin user input in the AdminID field being passed directly to a call to system.

    Source:Fidus InfoSecurity
    Published:1 May 2018
    7.8
    High

    CVE-2017-16997

    Last Modified: 20 Apr 2025

    elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and decompose_rpath functions. This is associated with misinterpretion of an empty RPATH/RUNPATH token as the "./" directory. NOTE: this configuration of RPATH/RUNPATH for a privileged program is apparently very uncommon; most likely, no such program is shipped with any common Linux distribution.

    Published:17 Dec 2017
    7.8
    High

    CVE-2017-16995

    Last Modified: 19 Jul 2018

    The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.

    Source:Metasploit
    Published:22 Dec 2017
    5.5
    Medium

    CVE-2017-16994

    Last Modified: 19 Mar 2018

    The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call.

    Source:anonymous
    Published:15 Nov 2017
    6.1
    Medium

    CVE-2017-16962

    Last Modified: 27 Nov 2017

    The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities via (1) the location or details field of a Google Calendar invitation, (2) a crafted Outlook.com calendar (aka Hotmail Calendar) invitation, (3) e-mail granting access to a directory that has JavaScript in its name, (4) JavaScript in a note name, (5) JavaScript in a task name, or (6) HTML e-mail that is mishandled in the Inbox component.

    Source:Boumediene KADDOUR
    Published:27 Nov 2017
    7.5
    High

    CVE-2017-16953

    Last Modified: 5 Dec 2017

    connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to modify the PPPoE configuration or set up a malicious configuration via a GET request.

    Source:Ibad Shah
    Published:1 Dec 2017
    5.5
    Medium

    CVE-2017-16952

    Last Modified: 27 Nov 2017

    KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.

    Source:R.Yavari
    Published:28 Nov 2017
    5.5
    Medium

    CVE-2017-16951

    Last Modified: 27 Nov 2017

    Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file.

    Source:R.Yavari
    Published:28 Nov 2017
    9.8
    Critical

    CVE-2017-16949

    Last Modified: 12 Dec 2017

    An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper input sanitization allows the attacker to override the settings for allowed file extensions and upload file size, related to inc/cores/file-uploader.php and file-uploader/file-uploader-class.php. This allows the attacker to upload anything they want to the server, as demonstrated by an action=ap_file_upload_action&allowedExtensions[]=php request to /wp-admin/admin-ajax.php that results in a .php file upload and resultant PHP code execution.

    Source:Colette Chamberland
    Published:18 Dec 2017
    7.8
    High

    CVE-2017-16945

    Last Modified: 29 Jan 2018

    The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted restore path.

    Source:Mark Wadham
    Published:31 Jan 2018
    7.5
    High

    CVE-2017-16944

    Last Modified: 27 Nov 2017

    The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character signifying the end of the content, related to the bdat_getc function.

    Source:meh
    Published:24 Nov 2017
    9.8
    Critical

    CVE-2017-16943

    Last Modified: 20 Apr 2025

    The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

    Published:23 Nov 2017
    7.8
    High

    CVE-2017-16939

    Last Modified: 15 Feb 2018

    The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM_MSG_GETPOLICY Netlink messages.

    Source:SecuriTeam
    Published:24 Nov 2017
    9.8
    Critical

    CVE-2017-16935

    Last Modified: 15 Feb 2018

    Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to bypass intended access restrictions via a direct request to /plugins/core-ui/servercomm/messages.xml, as demonstrated by changing the admin password by obtaining account details via a users/search.json request, and then modifying the account via an editUser request.

    Source:SecuriTeam
    Published:24 Nov 2017
    9.8
    Critical

    CVE-2017-16934

    Last Modified: 15 Feb 2018

    The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Basic Authentication needed for a change_password.csp request, which supports a "<%%25call system.exec:" string in the passwd parameter.

    Source:SecuriTeam
    Published:24 Nov 2017
    9.8
    Critical

    CVE-2017-16930

    Last Modified: 11 Jan 2018

    The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the request handler. This can be exploited via a long API request that is mishandled during logging.

    Source:tintinweb
    Published:5 Dec 2017
    8.1
    High

    CVE-2017-16929

    Last Modified: 11 Jan 2018

    The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a remote attacker to read/write arbitrary files. This can be exploited via ../ sequences in the pathname to miner_file or miner_getfile.

    Source:tintinweb
    Published:5 Dec 2017
    7.8
    High

    CVE-2017-16928

    Last Modified: 29 Jan 2018

    The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a crafted update URL, as demonstrated by file:///tmp/blah/Arq.zip.

    Source:Mark Wadham
    Published:31 Jan 2018
    8.8
    High

    CVE-2017-16921

    Last Modified: 22 Apr 2021

    In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.

    Source:Bæln0rn
    Published:8 Dec 2017
    7.5
    High

    CVE-2017-16902

    Last Modified: 22 Nov 2017

    On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.

    Source:Nu11By73
    Published:20 Nov 2017
    7.8
    High

    CVE-2017-16895

    Last Modified: 6 Dec 2017

    The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 for Mac allow local users to gain root privileges via a crafted data packet.

    Source:Mark Wadham
    Published:1 Dec 2017
    7.5
    High

    CVE-2017-16894

    Last Modified: 16 Jul 2019

    In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwords) via a direct request for the /.env URI. NOTE: this CVE is only about Laravel framework's writeNewEnvironmentFileWith function in src/Illuminate/Foundation/Console/KeyGenerateCommand.php, which uses file_put_contents without restricting the .env permissions. The .env filename is not used exclusively by Laravel framework.

    Source:Metasploit
    Published:20 Nov 2017
    9.8
    Critical

    CVE-2017-16887

    Last Modified: 8 Jan 2018

    The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.

    Source:Ibad Shah
    Published:12 Jan 2018
    8.8
    High

    CVE-2017-16886

    Last Modified: 8 Jan 2018

    The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services via CSRF can result in an unauthorized change of username or password of the administrator of the portal.

    Source:Ibad Shah
    Published:12 Jan 2018
    9.8
    Critical

    CVE-2017-16885

    Last Modified: 8 Jan 2018

    Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Changing Passwords, etc.) allows remote attackers to look for the information without authenticating. The information includes Version of device, Firmware ID, Connected users to device along their MAC Addresses, etc.

    Source:Ibad Shah
    Published:12 Jan 2018
    6.1
    Medium

    CVE-2017-16884

    Last Modified: 1 Dec 2017

    Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.

    Source:hyp3rlinx
    Published:6 Dec 2017
    5.4
    Medium

    CVE-2017-16843

    Last Modified: 19 Nov 2017

    Vonage VDV-23 115 3.2.11-0.9.40 devices have stored XSS via the NewKeyword or NewDomain field to /goform/RgParentalBasic.

    Source:Nu11By73
    Published:16 Nov 2017
    6.1
    Medium

    CVE-2017-16841

    Last Modified: 16 Nov 2017

    LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.

    Source:Miguel Mendez Z
    Published:16 Nov 2017
    6.1
    Medium

    CVE-2017-16836

    Last Modified: 16 Nov 2017

    Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.

    Source:Nu11By73
    Published:16 Nov 2017
    5.4
    Medium

    CVE-2017-16819

    Last Modified: 22 Nov 2017

    A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) that is then reflected in multiple pages where that field data is utilized, resulting in session hijacking and possible elevation of privileges.

    Source:Keith Thome
    Published:17 Nov 2017
    5.4
    Medium

    CVE-2017-16807

    Last Modified: 17 Nov 2017

    A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.

    Source:Ishaq Mohammed
    Published:13 Nov 2017