9.8
    Critical

    CVE-2017-14243

    Last Modified: 18 Sept 2017

    An authentication bypass vulnerability on UTStar WA3002G4 ADSL Broadband Modem WA3002G4-0021.01 devices allows attackers to directly access administrative settings and obtain cleartext credentials from HTML source, as demonstrated by info.cgi, upload.cgi, backupsettings.cgi, pppoe.cgi, resetrouter.cgi, and password.cgi.

    Source:Gem George
    Published:17 Sept 2017
    6.1
    Medium

    CVE-2017-14219

    Last Modified: 8 Sept 2017

    XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless credentials without being connected to the network, related to userRpm/popupSiteSurveyRpm.htm and userRpm/WlanSecurityRpm.htm. The attack vector is a crafted ESSID, as demonstrated by an "airbase-ng -e" command.

    Source:Elber Tavares
    Published:7 Sept 2017
    6.2
    Medium

    CVE-2017-14187

    Last Modified: 21 Nov 2024

    A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.

    Published:24 May 2018
    7.8
    High

    CVE-2017-14153

    Last Modified: 8 Sept 2017

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824b7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in a kernel pool overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Source:mr_me
    Published:11 Sept 2017
    9.8
    Critical

    CVE-2017-14147

    Last Modified: 11 Sept 2017

    An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. Due to improper authentication on this page, the software accepts the request hence allowing attacker to reset the router to its default configurations which later could allow attacker to login to router by using default username/password.

    Source:Ibad Shah
    Published:7 Sept 2017
    9.8
    Critical

    CVE-2017-14143

    Last Modified: 24 Jan 2018

    The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, which allows remote attackers to bypass an intended protection mechanism and consequently conduct PHP object injection attacks and execute arbitrary PHP code via a crafted userzone cookie.

    Source:Metasploit
    Published:19 Sept 2017
    6.1
    Medium

    CVE-2017-14126

    Last Modified: 5 Sept 2017

    The Participants Database plugin before 1.7.5.10 for WordPress has XSS.

    Source:Benjamin Lim
    Published:4 Sept 2017
    7.8
    High

    CVE-2017-14105

    Last Modified: 20 Apr 2025

    HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature does not validate pathnames within the archive. An authenticated, local attacker - even restricted as a tenant - can add a jsp at HiveManager/tomcat/webapps/hm/domains/$yourtenant/maps (it will be exposed at the web interface).

    Published:1 Sept 2017
    9.8
    Critical

    CVE-2017-14097

    Last Modified: 22 Dec 2017

    An improper access control vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to decrypt contents of a database with information that could be used to access a vulnerable system.

    Source:CoreLabs
    Published:19 Jan 2018
    6.1
    Medium

    CVE-2017-14096

    Last Modified: 22 Dec 2017

    A stored cross site scripting (XSS) vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to execute a malicious payload on vulnerable systems.

    Source:CoreLabs
    Published:19 Jan 2018
    8.1
    High

    CVE-2017-14095

    Last Modified: 22 Dec 2017

    A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a local file inclusion on a vulnerable system.

    Source:CoreLabs
    Published:19 Jan 2018
    9.8
    Critical

    CVE-2017-14094

    Last Modified: 22 Dec 2017

    A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could allow an attacker to perform remote command execution via a cron job injection on a vulnerable system.

    Source:CoreLabs
    Published:19 Jan 2018
    9.8
    Critical

    CVE-2017-14089

    Last Modified: 29 Sept 2017

    An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the OfficeScan server to target cgiShowClientAdm.exe and cause memory corruption issues.

    Source:hyp3rlinx
    Published:5 Oct 2017
    7.5
    High

    CVE-2017-14087

    Last Modified: 28 Sept 2017

    A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Host header, allowing the attacker to render arbitrary links that point to a malicious website with poisoned Host header webpages.

    Source:hyp3rlinx
    Published:5 Oct 2017
    7.5
    High

    CVE-2017-14086

    Last Modified: 28 Sept 2017

    Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to start the fcgiOfcDDA.exe executable or cause a potential INI corruption, which may cause the server disk space to be consumed with dump files from continuous HTTP requests.

    Source:hyp3rlinx
    Published:5 Oct 2017
    5.3
    Medium

    CVE-2017-14085

    Last Modified: 28 Sept 2017

    Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to query the network's NT domain or the PHP version and modules.

    Source:hyp3rlinx
    Published:5 Oct 2017
    8.1
    High

    CVE-2017-14084

    Last Modified: 11 Jan 2018

    A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.

    Source:hyp3rlinx
    Published:5 Oct 2017
    7.5
    High

    CVE-2017-14083

    Last Modified: 28 Sept 2017

    A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.

    Source:hyp3rlinx
    Published:5 Oct 2017
    7.8
    High

    CVE-2017-14075

    Last Modified: 9 Sept 2017

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x953824a7 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in an out-of-bounds write condition. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Source:mr_me
    Published:11 Sept 2017
    7.5
    High

    CVE-2017-14063

    Last Modified: 20 Apr 2025

    Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if a '?' character occurs in a fragment identifier. Similar bugs were previously identified in cURL (CVE-2016-8624) and Oracle Java 8 java.net.URL.

    Published:28 Aug 2017
    6.3
    Medium

    CVE-2017-14016

    Last Modified: 14 Dec 2017

    A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The application lacks proper validation of the length of user-supplied data prior to copying it to a stack-based buffer, which could allow an attacker to execute arbitrary code under the context of the process.

    Source:Metasploit
    Published:6 Nov 2017
    7.1
    High

    CVE-2017-13878

    Last Modified: 19 Jan 2018

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (out-of-bounds read and system crash).

    Source:Google Security Research
    Published:25 Dec 2017
    7.8
    High

    CVE-2017-13876

    Last Modified: 12 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    7.8
    High

    CVE-2017-13875

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read) via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    8.1
    High

    CVE-2017-13872

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain administrator access without a password via certain interactions involving entry of the root user name.

    Source:Lemiorhan
    Published:29 Nov 2017
    5.5
    Medium

    CVE-2017-13869

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    5.5
    Medium

    CVE-2017-13868

    Last Modified: 3 Mar 2018

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Brandon Azad
    Published:25 Dec 2017
    7.8
    High

    CVE-2017-13867

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    5.5
    Medium

    CVE-2017-13865

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    7.8
    High

    CVE-2017-13861

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "IOSurface" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    5.5
    Medium

    CVE-2017-13855

    Last Modified: 19 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. watchOS before 4.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app that triggers type confusion.

    Source:Google Security Research
    Published:25 Dec 2017
    5.5
    Medium

    CVE-2017-13849

    Last Modified: 20 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service (application crash) via a crafted text file.

    Source:Russian Otter
    Published:13 Nov 2017
    7.8
    High

    CVE-2017-13847

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The issue involves the "IOKit" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:25 Dec 2017
    8.8
    High

    CVE-2017-13802

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13798

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13797

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13796

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13795

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13794

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13792

    Last Modified: 18 Jan 2018

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13791

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13785

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13784

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13783

    Last Modified: 22 Nov 2017

    An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:13 Nov 2017
    8.8
    High

    CVE-2017-13772

    Last Modified: 5 Nov 2020

    Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.

    Source:Patrik Lantz
    Published:23 Oct 2017
    5.4
    Medium

    CVE-2017-13754

    Last Modified: 4 Sept 2017

    Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter before 6.50b allows remote attackers to inject arbitrary web script or HTML via the "server name" field in actions/ChangeConfiguration.html.

    Source:Vulnerability-Lab
    Published:7 Sept 2017
    8.8
    High

    CVE-2017-13713

    Last Modified: 4 Sept 2017

    T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user parameter to cgi-bin/webupg.

    Source:Hay Mizrachi
    Published:7 Sept 2017
    5.5
    Medium

    CVE-2017-13672

    Last Modified: 20 Apr 2025

    QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) via vectors involving display update.

    Published:24 Aug 2017
    7.8
    High

    CVE-2017-13286

    Last Modified: 21 Nov 2024

    In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-69683251.

    Published:4 Apr 2018
    6.5
    Medium

    CVE-2017-13262

    Last Modified: 23 Mar 2018

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69271284.

    Source:QuarksLab
    Published:4 Apr 2018