7
    High

    CVE-2017-9644

    Last Modified: 23 Aug 2017

    An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An unquoted search path vulnerability may allow a non-privileged local attacker to change files in the installation directory and execute arbitrary code with elevated privileges.

    Source:LiquidWorm
    Published:25 Aug 2017
    6.3
    Medium

    CVE-2017-9640

    Last Modified: 23 Aug 2017

    A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.

    Source:LiquidWorm
    Published:25 Aug 2017
    8.6
    High

    CVE-2017-9627

    Last Modified: 20 Apr 2025

    An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The uncontrolled resource consumption vulnerability could allow an attacker to exhaust the memory resources of the machine, causing a denial of service.

    Published:7 Jul 2017
    8.8
    High

    CVE-2017-9614

    Last Modified: 28 Jul 2017

    The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse of the libjpeg API

    Source:qflb.wu
    Published:26 Jul 2017
    5.4
    Medium

    CVE-2017-9609

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Blackcat CMS 1.2 allows remote authenticated users to inject arbitrary web script or HTML via the map_language parameter to backend/pages/lang_settings.php.

    Published:17 Jul 2017
    6.5
    Medium

    CVE-2017-9608

    Last Modified: 20 Apr 2025

    The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.

    Published:27 Dec 2017
    7.3
    High

    CVE-2017-9606

    Last Modified: 20 Apr 2025

    Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.

    Published:15 Jun 2017
    8.8
    High

    CVE-2017-9603

    Last Modified: 14 Jun 2017

    SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.

    Source:Dimitrios Tsagkarakis
    Published:13 Jun 2017
    9.8
    Critical

    CVE-2017-9602

    Last Modified: 16 Jun 2017

    KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthenticated user can access the file upload and deletion functionality. Through this functionality, a user can upload an ASPX script to Uploads/Documents/ to run any arbitrary code.

    Source:Fatih Emiral
    Published:16 Jun 2017
    5.3
    Medium

    CVE-2017-9554

    Last Modified: 9 Jan 2018

    An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allows remote attackers to enumerate valid usernames via unspecified vectors.

    Source:Steve Kaun
    Published:24 Jul 2017
    9.8
    Critical

    CVE-2017-9544

    Last Modified: 20 Apr 2025

    There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code.

    Published:12 Jun 2017
    5.4
    Medium

    CVE-2017-9516

    Last Modified: 9 Jun 2017

    Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

    Source:Ahsan Tahir
    Published:8 Jun 2017
    6.1
    Medium

    CVE-2017-9506

    Last Modified: 20 Apr 2025

    The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before version 2.0.4 allows remote attackers to access the content of internal network resources and/or perform an XSS attack via Server Side Request Forgery (SSRF).

    Published:23 Aug 2017
    6.5
    Medium

    CVE-2017-9476

    Last Modified: 20 Apr 2025

    The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices makes it easy for remote attackers to determine the hidden SSID and passphrase for a Home Security Wi-Fi network.

    Published:31 Jul 2017
    9.8
    Critical

    CVE-2017-9430

    Last Modified: 3 Aug 2017

    Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.

    Source:FarazPajohan
    Published:5 Jun 2017
    8.8
    High

    CVE-2017-9429

    Last Modified: 28 Oct 2017

    SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitrary SQL commands via the id parameter to wp-admin/admin.php.

    Source:Dimitrios Tsagkarakis
    Published:13 Jun 2017
    8.8
    High

    CVE-2017-9418

    Last Modified: 13 Jun 2017

    SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute arbitrary SQL commands via the testid parameter to wp-admin/admin.php.

    Source:Dimitrios Tsagkarakis
    Published:12 Jun 2017
    9.8
    Critical

    CVE-2017-9417

    Last Modified: 9 Mar 2018

    Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

    Source:649
    Published:3 Jun 2017
    7.5
    High

    CVE-2017-9415

    Last Modified: 5 Jun 2017

    Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view.

    Source:hyp3rlinx
    Published:21 Jul 2017
    8.8
    High

    CVE-2017-9414

    Last Modified: 20 Jul 2018

    Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote attackers to hijack the authentication of unspecified victims for requests that conduct cross-site scripting (XSS) attacks or possibly have unspecified other impact via the name parameter to playerSettings.view.

    Source:hyp3rlinx
    Published:5 Feb 2018
    8.8
    High

    CVE-2017-9413

    Last Modified: 5 Jun 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attackers to hijack the authentication of users for requests that (1) subscribe to a podcast via the add parameter to podcastReceiverAdmin.view or (2) update Internet Radio Settings via the urlRedirectCustomUrl parameter to networkSettings.view. NOTE: These vulnerabilities can be exploited to conduct server-side request forgery (SSRF) attacks.

    Source:hyp3rlinx
    Published:25 Jul 2017
    5.5
    Medium

    CVE-2017-9412

    Last Modified: 28 Jul 2017

    The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.

    Source:qflb.wu
    Published:5 Feb 2015
    3.3
    Low

    CVE-2017-9411

    Last Modified: 28 Jul 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9100. Reason: This candidate is a duplicate of CVE-2015-9100. Notes: All CVE users should reference CVE-2015-9100 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:qflb.wu
    Published:5 Feb 2015
    3.3
    Low

    CVE-2017-9410

    Last Modified: 28 Jul 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-9101. Reason: This candidate is a duplicate of CVE-2015-9101. Notes: All CVE users should reference CVE-2015-9101 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:qflb.wu
    Published:5 Feb 2015
    8.8
    High

    CVE-2017-9380

    Last Modified: 11 Jun 2021

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.

    Source:Ron Jost
    Published:2 Jun 2017
    7.4
    High

    CVE-2017-9355

    Last Modified: 20 Jul 2018

    XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file.

    Source:hyp3rlinx
    Published:7 Jun 2017
    7.5
    High

    CVE-2017-9353

    Last Modified: 6 Jun 2017

    In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.

    Source:OSS-Fuzz
    Published:1 Jun 2017
    7.5
    High

    CVE-2017-9347

    Last Modified: 6 Jun 2017

    In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.

    Source:OSS-Fuzz
    Published:1 Jun 2017
    5.5
    Medium

    CVE-2017-9260

    Last Modified: 28 Jul 2017

    The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.

    Source:qflb.wu
    Published:26 Jul 2017
    5.5
    Medium

    CVE-2017-9259

    Last Modified: 28 Jul 2017

    The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted wav file.

    Source:qflb.wu
    Published:26 Jul 2017
    5.5
    Medium

    CVE-2017-9258

    Last Modified: 28 Jul 2017

    The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.

    Source:qflb.wu
    Published:26 Jul 2017
    9.8
    Critical

    CVE-2017-9248

    Last Modified: 26 Jan 2018

    Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

    Source:Paul Taylor
    Published:3 Jul 2017
    9.8
    Critical

    CVE-2017-9232

    Last Modified: 12 Feb 2018

    Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate permissions, allowing privilege escalation by users on the system to root.

    Source:Metasploit
    Published:28 May 2017
    5.5
    Medium

    CVE-2017-9150

    Last Modified: 31 May 2017

    The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.

    Source:Google Security Research
    Published:8 May 2017
    6.5
    Medium

    CVE-2017-9147

    Last Modified: 6 Jul 2017

    LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.

    Source:zhangtan
    Published:12 May 2017
    5.5
    Medium

    CVE-2017-9130

    Last Modified: 20 Jun 2017

    The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted wav file.

    Source:qflb.wu
    Published:21 Jun 2017
    5.5
    Medium

    CVE-2017-9129

    Last Modified: 20 Jun 2017

    The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.

    Source:qflb.wu
    Published:21 Jun 2017
    6.5
    Medium

    CVE-2017-9128

    Last Modified: 9 Jun 2017

    The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9127

    Last Modified: 9 Jun 2017

    The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9126

    Last Modified: 9 Jun 2017

    The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9125

    Last Modified: 9 Jun 2017

    The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9124

    Last Modified: 9 Jun 2017

    The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9123

    Last Modified: 9 Jun 2017

    The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    6.5
    Medium

    CVE-2017-9122

    Last Modified: 9 Jun 2017

    The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.

    Source:qflb.wu
    Published:12 Jun 2017
    9.8
    Critical

    CVE-2017-9101

    Last Modified: 9 May 2018

    import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.

    Source:Metasploit
    Published:21 May 2017
    9.1
    Critical

    CVE-2017-9097

    Last Modified: 20 Apr 2025

    In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote attacker to read or modify files through a path traversal technique, as demonstrated by reading the password file, or using the template parameter to cgi-bin/write.cgi to write to an arbitrary file.

    Published:16 Jun 2017
    8.8
    High

    CVE-2017-9096

    Last Modified: 20 Apr 2025

    The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML external entity (XXE) attacks via a crafted PDF.

    Published:6 Nov 2017
    5.5
    Medium

    CVE-2017-9095

    Last Modified: 27 Nov 2017

    XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

    Source:Trent Gordon
    Published:8 Sept 2017
    8.8
    High

    CVE-2017-9080

    Last Modified: 9 May 2018

    PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code Injection.

    Source:Metasploit
    Published:19 May 2017
    7.5
    High

    CVE-2017-9024

    Last Modified: 21 May 2017

    Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Traversal issue in its TFTP Server, allowing attackers to read arbitrary files via ../ sequences in a pathname.

    Source:hyp3rlinx
    Published:21 May 2017