7.5
    High

    CVE-2017-13261

    Last Modified: 23 Mar 2018

    In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177292.

    Source:QuarksLab
    Published:4 Apr 2018
    7.5
    High

    CVE-2017-13260

    Last Modified: 23 Mar 2018

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69177251.

    Source:QuarksLab
    Published:4 Apr 2018
    7.5
    High

    CVE-2017-13258

    Last Modified: 23 Mar 2018

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67863755.

    Source:QuarksLab
    Published:4 Apr 2018
    7.8
    High

    CVE-2017-13253

    Last Modified: 16 Mar 2018

    In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71389378.

    Source:Tamir Zahavi-Brunner
    Published:4 Apr 2018
    7.8
    High

    CVE-2017-13236

    Last Modified: 7 Feb 2018

    In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217699.

    Source:Google Security Research
    Published:12 Feb 2018
    7.8
    High

    CVE-2017-13216

    Last Modified: 9 Jan 2018

    In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-66954097.

    Source:Google Security Research
    Published:2 Jan 2018
    7.8
    High

    CVE-2017-13209

    Last Modified: 11 Jan 2018

    In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller which could allow an application or service to replace a HAL service with its own service. This could lead to a local elevation of privilege enabling code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-68217907.

    Source:Google Security Research
    Published:12 Jan 2018
    9.8
    Critical

    CVE-2017-13208

    Last Modified: 21 Nov 2024

    In receive_packet of libnetutils/packet.c, there is a possible out-of-bounds write due to a missing bounds check on the DHCP response. This could lead to remote code execution as a privileged process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-67474440.

    Published:12 Jan 2018
    7.8
    High

    CVE-2017-13156

    Last Modified: 8 Nov 2019

    An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-64211847.

    Source:Metasploit
    Published:6 Dec 2017
    8
    High

    CVE-2017-13129

    Last Modified: 20 Oct 2017

    Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hijack the authentication of administrators for requests that add administrators by leveraging lack of anti-CSRF tokens.

    Source:Arvind V
    Published:26 Sept 2017
    8.8
    High

    CVE-2017-13089

    Last Modified: 20 Apr 2025

    The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the chunk length is a non-negative number. The code then tries to skip the chunk in pieces of 512 bytes by using the MIN() macro, but ends up passing the negative chunk length to connect.c:fd_read(). As fd_read() takes an int argument, the high 32 bits of the chunk length are discarded, leaving fd_read() with a completely attacker controlled length argument.

    Published:26 Oct 2017
    7.5
    High

    CVE-2017-13068

    Last Modified: 15 Feb 2018

    QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.

    Source:SecuriTeam
    Published:6 Oct 2017
    7.8
    High

    CVE-2017-13056

    Last Modified: 27 Sept 2017

    The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.

    Source:Daniele Votta
    Published:27 Dec 2017
    6.1
    Medium

    CVE-2017-12984

    Last Modified: 21 Aug 2017

    PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.

    Source:小雨
    Published:21 Aug 2017
    6.1
    Medium

    CVE-2017-12971

    Last Modified: 21 Aug 2017

    Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or HTML via the account parameter to phpsftpd/users.php.

    Source:hyp3rlinx
    Published:23 Aug 2017
    8.8
    High

    CVE-2017-12970

    Last Modified: 21 Aug 2017

    Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authentication of authenticated users for requests that (1) add or (2) delete user accounts via a request to phpsftpd/users.php.

    Source:hyp3rlinx
    Published:23 Aug 2017
    8.8
    High

    CVE-2017-12969

    Last Modified: 26 Nov 2017

    Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.

    Source:hyp3rlinx
    Published:9 Nov 2017
    9.8
    Critical

    CVE-2017-12965

    Last Modified: 21 Aug 2017

    Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Source:hyp3rlinx
    Published:23 Aug 2017
    6.5
    Medium

    CVE-2017-12954

    Last Modified: 24 Aug 2017

    The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.

    Source:qflb.wu
    Published:28 Aug 2017
    6.5
    Medium

    CVE-2017-12953

    Last Modified: 24 Aug 2017

    The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.

    Source:qflb.wu
    Published:28 Aug 2017
    6.5
    Medium

    CVE-2017-12952

    Last Modified: 24 Aug 2017

    The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

    Source:qflb.wu
    Published:28 Aug 2017
    6.5
    Medium

    CVE-2017-12951

    Last Modified: 24 Aug 2017

    The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.

    Source:qflb.wu
    Published:28 Aug 2017
    6.5
    Medium

    CVE-2017-12950

    Last Modified: 24 Aug 2017

    The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

    Source:qflb.wu
    Published:28 Aug 2017
    8.8
    High

    CVE-2017-12945

    Last Modified: 29 Nov 2019

    Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authenticated attackers to execute arbitrary commands as root.

    Source:Alexandre Teyar
    Published:27 Nov 2019
    9.8
    Critical

    CVE-2017-12943

    Last Modified: 29 Aug 2017

    D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?REQUIRE_FILE= absolute path traversal attack, as demonstrated by discovering the admin password.

    Source:Jithin D Kurup
    Published:18 Aug 2017
    9.8
    Critical

    CVE-2017-12930

    Last Modified: 20 Sept 2017

    SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users to access the web interface as administrator via a crafted password.

    Source:Simon Brannstrom
    Published:21 Sept 2017
    8.8
    High

    CVE-2017-12929

    Last Modified: 20 Sept 2017

    Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users to upload arbitrary files leading to Remote Command Execution.

    Source:Simon Brannstrom
    Published:21 Sept 2017
    9.8
    Critical

    CVE-2017-12865

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

    Published:29 Aug 2017
    Unknown

    CVE-2017-12854

    https://www.exploit-db.com/exploits/44065

    7.5
    High

    CVE-2017-12852

    Last Modified: 20 Apr 2025

    The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will stick into an infinite loop, which can allow attackers to cause a DoS attack.

    Published:15 Aug 2017
    6.1
    Medium

    CVE-2017-12792

    Last Modified: 20 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in NexusPHP 1.5 allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) linkname, (2) url, or (3) title parameter in an add action to linksmanage.php.

    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-12787

    Last Modified: 23 Aug 2017

    A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because incoming packet data can contain embedded OS commands, and can also trigger a stack-based buffer overflow.

    Source:François Goichon
    Published:22 Aug 2017
    9.8
    Critical

    CVE-2017-12786

    Last Modified: 23 Aug 2017

    Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when ACL modifications are applied. This could be leveraged by remote, unauthenticated attackers to gain resultant privileged (root) code execution on the switch, because there is a stack-based buffer overflow during unserialization of packet data.

    Source:François Goichon
    Published:22 Aug 2017
    9.8
    Critical

    CVE-2017-12785

    Last Modified: 23 Aug 2017

    The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, is prone to a buffer overflow in the "show log cli" command. This could be used by a read-only user (monitor role) to gain privileged (root) code execution on the switch via command injection.

    Source:François Goichon
    Published:22 Aug 2017
    8.8
    High

    CVE-2017-12763

    Last Modified: 3 Oct 2017

    An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.

    Source:Daniele Linguaglossa
    Published:29 Aug 2017
    8.1
    High

    CVE-2017-12718

    Last Modified: 18 Jan 2018

    A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party component used in the pump does not verify input buffer size prior to copying, leading to a buffer overflow, allowing remote code execution on the target device. The pump receives the potentially malicious input infrequently and under certain conditions, increasing the difficulty of exploitation.

    Source:Scott Gayou
    Published:15 Feb 2018
    7.8
    High

    CVE-2017-12653

    Last Modified: 15 Feb 2018

    360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.

    Source:SecuriTeam
    Published:7 Aug 2017
    7.5
    High

    CVE-2017-12637

    Last Modified: 22 Apr 2026

    Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in the wild in August 2017, aka SAP Security Note 2486657.

    Published:7 Aug 2017
    7.2
    High

    CVE-2017-12636

    Last Modified: 13 Jul 2018

    CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an admin user in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to execute arbitrary shell commands as the CouchDB user, including downloading and executing scripts from the public internet.

    Source:Metasploit
    Published:14 Nov 2017
    9.8
    Critical

    CVE-2017-12635

    Last Modified: 13 Jul 2018

    Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, including the special case '_admin' role, that denotes administrative users. In combination with CVE-2017-12636 (Remote Code Execution), this can be used to give non-admin users access to arbitrary shell commands on the server as the database system user. The JSON parser differences result in behaviour that if two 'roles' keys are available in the JSON, the second one will be used for authorising the document write, but the first 'roles' key is used for subsequent authorization for the newly created user. By design, users can not assign themselves roles. The vulnerability allows non-admin users to give themselves admin privileges.

    Source:Metasploit
    Published:14 Nov 2017
    9.8
    Critical

    CVE-2017-12629

    Last Modified: 17 Oct 2017

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

    Source:Michael Stepankin & Olga Barinova
    Published:12 Oct 2017
    5.5
    Medium

    CVE-2017-12624

    Last Modified: 20 Apr 2025

    Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

    Published:14 Nov 2017
    8.1
    High

    CVE-2017-12617

    Last Modified: 17 Oct 2017

    When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    Source:Metasploit
    Published:21 Sept 2017
    8.1
    High

    CVE-2017-12615

    Last Modified: 4 Oct 2017

    When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.

    Source:xxlegend
    Published:19 Sept 2017
    9.8
    Critical

    CVE-2017-12611

    Last Modified: 11 Sept 2018

    In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

    Source:brianwrf
    Published:7 Sept 2017
    7.8
    High

    CVE-2017-12579

    Last Modified: 6 Dec 2017

    An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.

    Source:Mark Wadham
    Published:19 Oct 2017
    9.8
    Critical

    CVE-2017-12561

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in HPE intelligent Management Center (iMC) PLAT version Plat 7.3 E0504P4 and earlier was found.

    Published:15 Feb 2018
    9.8
    Critical

    CVE-2017-12557

    Last Modified: 4 Dec 2018

    A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and earlier was found.

    Source:Metasploit
    Published:15 Feb 2018
    10
    Critical

    CVE-2017-12542

    Last Modified: 9 Feb 2018

    A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.

    Source:skelsec
    Published:15 Feb 2018
    8.8
    High

    CVE-2017-12500

    Last Modified: 18 May 2018

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found. The problem was resolved in HPE Intelligent Management Center PLAT v7.3 (E0506) or any subsequent version.

    Source:TrendyTofu
    Published:15 Feb 2018