8.6
    High

    CVE-2017-15644

    Last Modified: 10 Dec 2017

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

    Source:hyp3rlinx
    Published:19 Oct 2017
    7.4
    High

    CVE-2017-15643

    Last Modified: 15 Feb 2018

    An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleartext HTTP for updates along with a CRC32 checksum and an update value for verification of the downloaded files. The attacker first forces the client to initiate an update transaction by modifying an update field within an HTTP 200 response, so that it refers to a nonexistent update. The attacker then modifies the HTTP 404 response so that it specifies a successfully found update, with a Trojan horse executable file (e.g., guardxup.exe) and the correct CRC32 checksum for that file.

    Source:SecuriTeam
    Published:19 Oct 2017
    6.5
    Medium

    CVE-2017-15639

    Last Modified: 25 Oct 2017

    tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.

    Source:Anthony Cole
    Published:19 Oct 2017
    8.8
    High

    CVE-2017-15595

    Last Modified: 16 Nov 2017

    An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking.

    Source:Google Security Research
    Published:12 Oct 2017
    9.8
    Critical

    CVE-2017-15580

    Last Modified: 8 Aug 2018

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.

    Source:Rajwinder Singh
    Published:23 Oct 2017
    9.8
    Critical

    CVE-2017-15579

    Last Modified: 15 Feb 2018

    In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.

    Source:SecuriTeam
    Published:18 Oct 2017
    8.8
    High

    CVE-2017-15578

    Last Modified: 15 Feb 2018

    In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.

    Source:SecuriTeam
    Published:18 Oct 2017
    8.8
    High

    CVE-2017-15428

    Last Modified: 21 Nov 2024

    Insufficient data validation in V8 builtins string generator could lead to out of bounds read and write access in V8 in Google Chrome prior to 62.0.3202.94 and allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published:9 Jan 2019
    6.5
    Medium

    CVE-2017-15394

    Last Modified: 21 Nov 2024

    Insufficient Policy Enforcement in Extensions in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform domain spoofing in permission dialogs via IDN homographs in a crafted Chrome Extension.

    Published:17 Oct 2017
    6.1
    Medium

    CVE-2017-15374

    Last Modified: 21 Jan 2018

    Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management system backend modules. Remote attackers are able to inject malicious script code into the firstname, lastname, or order input fields to provoke persistent execution in the customer and orders section of the backend. The execution occurs in the administrator backend listing when processing a preview of the customers (kunden) or orders (bestellungen). The injection can be performed interactively via user registration or by manipulation of the order information inputs. The issue can be exploited by low privileged user accounts against higher privileged (admin or moderator) accounts.

    Source:Vulnerability-Lab
    Published:16 Oct 2017
    9.8
    Critical

    CVE-2017-15367

    Last Modified: 9 Mar 2018

    Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access the Bacula database and, depending on configuration, escalate privileges on the server.

    Source:Gustavo Sorondo
    Published:7 Mar 2018
    5.9
    Medium

    CVE-2017-15361

    Last Modified: 20 Apr 2025

    The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA. Examples of affected technologies include BitLocker with TPM 1.2, YubiKey 4 (before 4.3.5) PGP key generation, and the Cached User Data encryption feature in Chrome OS.

    Published:16 Oct 2017
    6.5
    Medium

    CVE-2017-15359

    Last Modified: 17 Oct 2017

    In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/RecordingList/DownloadRecord?file=" and "/api/SupportInfo?file=" are the vulnerable parameters. An attacker must be authenticated to exploit this issue to access sensitive information to aid in subsequent attacks.

    Source:Jens Regel
    Published:18 Oct 2017
    7
    High

    CVE-2017-15358

    Last Modified: 30 Jul 2018

    Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privileges via vectors involving the --self-repair option.

    Source:Mark Wadham
    Published:3 Aug 2018
    7.4
    High

    CVE-2017-15357

    Last Modified: 6 Dec 2017

    The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.

    Source:Mark Wadham
    Published:1 Dec 2017
    7.8
    High

    CVE-2017-15303

    Last Modified: 20 Apr 2025

    In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because any program running on the local machine (while CPU-Z is running) can issue an ioctl 0x9C402430 call to the kernel-mode driver (e.g., cpuz141_x64.sys for version 1.41).

    Published:16 Oct 2017
    6.1
    Medium

    CVE-2017-15291

    Last Modified: 23 Oct 2017

    Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.

    Source:Thiago Sena
    Published:20 Oct 2017
    6.1
    Medium

    CVE-2017-15287

    Last Modified: 13 Oct 2017

    There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouquets" field, or the file parameter to the /file URI.

    Source:Thiago Sena
    Published:12 Oct 2017
    5.4
    Medium

    CVE-2017-15284

    Last Modified: 17 Nov 2017

    Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG file containing malicious code as the Avatar for the profile. When this is opened by the Admin, it causes JavaScript execution in the context of the Admin account.

    Source:Ishaq Mohammed
    Published:12 Oct 2017
    6.5
    Medium

    CVE-2017-15277

    Last Modified: 20 Apr 2025

    ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette.

    Published:21 Jul 2017
    8.8
    High

    CVE-2017-15276

    Last Modified: 17 Oct 2017

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR archives). When unpacking TAR archives, Content Server fails to verify the contents of an archive, which causes a path traversal vulnerability via symlinks. Because some files on the Content Server filesystem are security-sensitive, this leads to privilege escalation.

    Source:Andrey B. Panfilov
    Published:13 Oct 2017
    5.9
    Medium

    CVE-2017-15271

    Last Modified: 14 Nov 2017

    A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did not automatically restart, which enabled attackers to perform a very effective DoS attack against this service. By sending a crafted SSH identification / version string to the server, a NULL pointer dereference could be caused, apparently because of a race condition in the window message handling, performing the cleanup for invalid connections. This incorrect cleanup code has a use-after-free.

    Source:X41 D-Sec GmbH
    Published:15 Nov 2017
    5.3
    Medium

    CVE-2017-15270

    Last Modified: 14 Nov 2017

    The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graphical User Interface (GUI) view and create arbitrary entries to a certain extent. Special characters such as '"' and ',' and '\r' are not escaped and can be used to add new entries to the log.

    Source:X41 D-Sec GmbH
    Published:15 Nov 2017
    7.5
    High

    CVE-2017-15236

    Last Modified: 15 Feb 2018

    Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config* files and extendword.txt.

    Source:SecuriTeam
    Published:11 Oct 2017
    7.5
    High

    CVE-2017-15235

    Last Modified: 15 Feb 2018

    The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact filename.

    Source:SecuriTeam
    Published:11 Oct 2017
    5.3
    Medium

    CVE-2017-15223

    Last Modified: 23 Oct 2017

    Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite loop.

    Source:Berk Cem Göksel
    Published:24 Oct 2017
    9.8
    Critical

    CVE-2017-15222

    Last Modified: 5 Jan 2018

    Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.

    Source:Metasploit
    Published:24 Oct 2017
    7.8
    High

    CVE-2017-15221

    Last Modified: 13 Mar 2019

    ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.

    Source:Parichay Rai
    Published:16 Oct 2017
    9.8
    Critical

    CVE-2017-15220

    Last Modified: 11 Oct 2017

    Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary code.

    Source:Revnic Vasile
    Published:11 Oct 2017
    7.5
    High

    CVE-2017-15120

    Last Modified: 21 Nov 2024

    An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a denial of service.

    Published:27 Jul 2018
    8.3
    High

    CVE-2017-15118

    Last Modified: 29 Nov 2017

    A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client to request an export name of size up to 4096 bytes, which in fact should be limited to 256 bytes, causing an out-of-bounds stack write in the qemu process. If NBD server requires TLS, the attacker cannot trigger the buffer overflow without first successfully negotiating TLS.

    Source:Eric Blake
    Published:28 Nov 2017
    6.5
    Medium

    CVE-2017-15099

    Last Modified: 20 Apr 2025

    INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

    Published:9 Nov 2017
    9.8
    Critical

    CVE-2017-15095

    Last Modified: 21 Nov 2024

    A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting more classes that could be used maliciously.

    Published:2 Nov 2017
    6.5
    Medium

    CVE-2017-15084

    Last Modified: 22 Aug 2020

    The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.

    Source:Dhiraj Mishra
    Published:6 Oct 2017
    Low

    CVE-2017-15083

    Last Modified: 13 Mar 2019

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1642. Reason: This candidate is a reservation duplicate of CVE-2009-1642.2. Notes: All CVE users should reference CVE-2009-1642 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Nitesh Shilpkar
    Published:11 Oct 2017
    9.8
    Critical

    CVE-2017-15081

    Last Modified: 30 Oct 2017

    In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.

    Source:Venkat Rajgor
    Published:24 Oct 2017
    8.8
    High

    CVE-2017-15049

    Last Modified: 21 Dec 2017

    The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

    Source:Conviso
    Published:19 Dec 2017
    8.8
    High

    CVE-2017-15048

    Last Modified: 21 Dec 2017

    Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote attackers to execute arbitrary code by leveraging the zoommtg:// scheme handler.

    Source:Conviso
    Published:19 Dec 2017
    7.5
    High

    CVE-2017-15035

    Last Modified: 8 Oct 2017

    EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).

    Source:Kevin McGuigan
    Published:5 Oct 2017
    4.3
    Medium

    CVE-2017-15014

    Last Modified: 17 Oct 2017

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an authenticated user uploads content to the repository, he performs the following steps: (1) calls the START_PUSH RPC-command; (2) uploads the file to the content server; (3) calls the END_PUSH_V2 RPC-command (here, Content Server returns a DATA_TICKET integer, intended to identify the location of the uploaded file on the Content Server filesystem); (4) creates a dmr_content object in the repository, which has a value of data_ticket equal to the value of DATA_TICKET returned at the end of END_PUSH_V2 call. As the result of this design, any authenticated user may create his own dmr_content object, pointing to already existing content in the Content Server filesystem.

    Source:Andrey B. Panfilov
    Published:13 Oct 2017
    8.8
    High

    CVE-2017-15013

    Last Modified: 19 Oct 2017

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server stores information about uploaded files in dmr_content objects, which are queryable and "editable" (before release 7.2P02, any authenticated user was able to edit dmr_content objects; now any authenticated user may delete a dmr_content object and then create a new one with the old identifier) by authenticated users; this allows any authenticated user to replace the content of security-sensitive dmr_content objects (for example, dmr_content related to dm_method objects) and gain superuser privileges.

    Source:Andrey B. Panfilov
    Published:13 Oct 2017
    8.8
    High

    CVE-2017-15012

    Last Modified: 17 Oct 2017

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the input of the PUT_FILE RPC-command, which allows any authenticated user to hijack an arbitrary file from the Content Server filesystem; because some files on the Content Server filesystem are security-sensitive, this leads to privilege escalation.

    Source:Andrey B. Panfilov
    Published:13 Oct 2017
    9.8
    Critical

    CVE-2017-14980

    Last Modified: 20 Apr 2025

    Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.

    Published:9 Oct 2017
    7.8
    High

    CVE-2017-14961

    Last Modified: 14 Nov 2017

    In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x8300000c.

    Source:Parvez Anwar
    Published:15 Nov 2017
    7.5
    High

    CVE-2017-14960

    Last Modified: 3 Jan 2018

    xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.

    Source:Pawel Gocyla
    Published:4 Jan 2018
    5.7
    Medium

    CVE-2017-14956

    Last Modified: 16 Oct 2017

    AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send out any report via email to a given address (either in PDF or XLS format). Since there is no anti-CSRF token protecting this functionality, it is vulnerable to Cross-Site Request Forgery attacks.

    Source:Julien Ahrens
    Published:18 Oct 2017
    5.9
    Medium

    CVE-2017-14955

    Last Modified: 20 Oct 2017

    Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

    Source:Julien Ahrens
    Published:25 Sept 2017
    5.5
    Medium

    CVE-2017-14954

    Last Modified: 20 Apr 2025

    The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local users to obtain sensitive information, and bypass the KASLR protection mechanism, via a crafted system call.

    Published:29 Sept 2017
    9.8
    Critical

    CVE-2017-14948

    Last Modified: 21 Nov 2024

    Certain D-Link products are affected by: Buffer Overflow. This affects DIR-880L 1.08B04 and DIR-895 L/R 1.13b03. The impact is: execute arbitrary code (remote). The component is: htdocs/fileaccess.cgi. The attack vector is: A crafted HTTP request handled by fileacces.cgi could allow an attacker to mount a ROP attack: if the HTTP header field CONTENT_TYPE starts with ''boundary=' followed by more than 256 characters, a buffer overflow would be triggered, potentially causing code execution.

    Published:14 Oct 2019
    5.5
    Medium

    CVE-2017-14939

    Last Modified: 11 Oct 2017

    decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.

    Source:Agostino Sarubbo
    Published:21 Sept 2017