7.5
    High

    CVE-2017-8982

    Last Modified: 18 May 2018

    A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.

    Source:TrendyTofu
    Published:15 Feb 2018
    8.8
    High

    CVE-2017-8928

    Last Modified: 15 May 2017

    mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.

    Source:hyp3rlinx
    Published:14 May 2017
    7.8
    High

    CVE-2017-8927

    Last Modified: 15 May 2017

    Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.

    Source:Muhann4d
    Published:15 May 2017
    7.8
    High

    CVE-2017-8926

    Last Modified: 15 May 2017

    Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.

    Source:Muhann4d
    Published:15 May 2017
    5.5
    Medium

    CVE-2017-8918

    Last Modified: 18 Aug 2017

    XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.

    Source:Trent Gordon
    Published:12 Sept 2017
    9.8
    Critical

    CVE-2017-8917

    Last Modified: 22 May 2017

    SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors.

    Source:Mateus Lino
    Published:17 May 2017
    7.2
    High

    CVE-2017-8912

    Last Modified: 12 May 2017

    CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.

    Source:Osanda Malith Jayathissa
    Published:12 May 2017
    9.8
    Critical

    CVE-2017-8895

    Last Modified: 29 Jun 2017

    In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of service or remote code execution. An unauthenticated attacker can use this vulnerability to crash the agent or potentially take control of the agent process and then the system it is running on.

    Source:Metasploit
    Published:10 May 2017
    7.8
    High

    CVE-2017-8890

    Last Modified: 20 Apr 2025

    The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers to cause a denial of service (double free) or possibly have unspecified other impact by leveraging use of the accept system call.

    Published:9 May 2017
    6.5
    Medium

    CVE-2017-8871

    Last Modified: 9 Jun 2017

    The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.

    Source:qflb.wu
    Published:7 Jun 2017
    7.8
    High

    CVE-2017-8870

    Last Modified: 27 Jul 2017

    Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.

    Source:Muhann4d
    Published:27 Jul 2017
    7.8
    High

    CVE-2017-8869

    Last Modified: 24 Aug 2017

    Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.

    Source:Muhann4d
    Published:27 Jul 2017
    7.8
    High

    CVE-2017-8852

    Last Modified: 10 May 2017

    SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of data written is an arbitrary number found within the file. The vendor response is SAP Security Note 2441560.

    Source:Core Security
    Published:10 May 2017
    7.8
    High

    CVE-2017-8849

    Last Modified: 23 May 2017

    smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.

    Source:Stealth
    Published:17 May 2017
    8.1
    High

    CVE-2017-8841

    Last Modified: 6 Jun 2017

    Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The attack methodology is absolute path traversal in cgi-bin/MANGA/firmware_process.cgi via the upfile.path parameter.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    5.3
    Medium

    CVE-2017-8840

    Last Modified: 6 Jun 2017

    Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Address, Serial Number, HA Group ID, Virtual IP, and Submitted syncid.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    6.1
    Medium

    CVE-2017-8839

    Last Modified: 6 Jun 2017

    XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is guest/preview.cgi.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    6.1
    Medium

    CVE-2017-8838

    Last Modified: 6 Jun 2017

    XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    9.8
    Critical

    CVE-2017-8837

    Last Modified: 6 Jun 2017

    Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The files in question are /etc/waipass and /etc/roapass. In case one of these devices is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    8.8
    High

    CVE-2017-8836

    Last Modified: 6 Jun 2017

    CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute commands, if a logged in user visits a malicious website. This can for example be used to change the credentials of the administrative webinterface.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    9.8
    Critical

    CVE-2017-8835

    Last Modified: 6 Jun 2017

    SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. An attack vector is the bauth cookie to cgi-bin/MANGA/admin.cgi. One impact is enumeration of user accounts by observing whether a session ID can be retrieved from the sessions database.

    Source:X41 D-Sec GmbH
    Published:5 Jun 2017
    7.8
    High

    CVE-2017-8824

    Last Modified: 8 Dec 2017

    The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privileges or cause a denial of service (use-after-free) via an AF_UNSPEC connect system call during the DCCP_LISTEN state.

    Source:Mohamed Ghannam
    Published:5 Dec 2017
    9.8
    Critical

    CVE-2017-8809

    Last Modified: 20 Apr 2025

    api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnerability.

    Published:15 Nov 2017
    5.4
    Medium

    CVE-2017-8802

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.8.0 Beta2 might allow remote attackers to inject arbitrary web script or HTML via vectors related to the "Show Snippet" functionality.

    Published:16 Jan 2018
    9.8
    Critical

    CVE-2017-8798

    Last Modified: 11 Jan 2018

    Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

    Source:tintinweb
    Published:11 May 2017
    7.5
    High

    CVE-2017-8779

    Last Modified: 8 May 2017

    rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to port 111, aka rpcbomb.

    Source:Guido Vranken
    Published:3 May 2017
    7.5
    High

    CVE-2017-8770

    Last Modified: 28 Aug 2017

    There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesystem on the device via a crafted getpage parameter.

    Source:Hay Mizrachi
    Published:20 Sept 2017
    6.1
    Medium

    CVE-2017-8760

    Last Modified: 20 Apr 2025

    An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in courier/1000@/index.html with the auth_params parameter. The device tries to use internal WAF filters to stop specific XSS Vulnerabilities. However, these can be bypassed by using some modifications to the payloads, e.g., URL encoding.

    Published:5 May 2017
    7.8
    High

    CVE-2017-8759

    Last Modified: 13 Sept 2017

    Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."

    Source:Voulnet
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8755

    Last Modified: 21 Sept 2017

    Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8756, and CVE-2017-11764.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8751

    Last Modified: 16 Nov 2017

    Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8740

    Last Modified: 21 Sept 2017

    Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8729, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8734

    Last Modified: 19 Sept 2017

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8751, and CVE-2017-11766.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8731

    Last Modified: 19 Sept 2017

    Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8734, CVE-2017-8751, and CVE-2017-11766.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8729

    Last Modified: 21 Sept 2017

    Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8649, CVE-2017-8660, CVE-2017-8738, CVE-2017-8740, CVE-2017-8741, CVE-2017-8748, CVE-2017-8752, CVE-2017-8753, CVE-2017-8755, CVE-2017-8756, and CVE-2017-11764.

    Source:Google Security Research
    Published:13 Sept 2017
    4.7
    Medium

    CVE-2017-8708

    Last Modified: 18 Sept 2017

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8679, CVE-2017-8709, and CVE-2017-8719.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8687

    Last Modified: 18 Sept 2017

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8677, and CVE-2017-8681.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8685

    Last Modified: 18 Sept 2017

    Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8684 and CVE-2017-8688.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8684

    Last Modified: 18 Sept 2017

    Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1, allows information disclosure by the way it discloses kernel memory addresses, aka "Windows GDI+ Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8685 and CVE-2017-8688.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8683

    Last Modified: 22 Nov 2017

    Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8682.

    Source:Google Security Research
    Published:13 Sept 2017
    8.8
    High

    CVE-2017-8682

    Last Modified: 22 Nov 2017

    Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8681

    Last Modified: 18 Sept 2017

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8680, CVE-2017-8677, and CVE-2017-8687.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8680

    Last Modified: 18 Sept 2017

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8678, CVE-2017-8677, CVE-2017-8681, and CVE-2017-8687.

    Source:Google Security Research
    Published:13 Sept 2017
    5.5
    Medium

    CVE-2017-8678

    Last Modified: 18 Sept 2017

    The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnerability when it improperly handles objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8677, CVE-2017-8680, CVE-2017-8681, and CVE-2017-8687.

    Source:Google Security Research
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-8671

    Last Modified: 17 Aug 2017

    Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8670, CVE-2017-8672, and CVE-2017-8674.

    Source:Google Security Research
    Published:8 Aug 2017
    7.5
    High

    CVE-2017-8670

    Last Modified: 17 Aug 2017

    Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8657, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.

    Source:Google Security Research
    Published:8 Aug 2017
    7.8
    High

    CVE-2017-8665

    Last Modified: 17 Aug 2017

    The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege Vulnerability."

    Source:Securify
    Published:15 Aug 2017
    7.5
    High

    CVE-2017-8657

    Last Modified: 17 Aug 2017

    Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8656, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.

    Source:Google Security Research
    Published:8 Aug 2017
    7.5
    High

    CVE-2017-8656

    Last Modified: 17 Aug 2017

    Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user due to the way that Microsoft browser JavaScript engines render content when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8634, CVE-2017-8635, CVE-2017-8636, CVE-2017-8638, CVE-2017-8639, CVE-2017-8640, CVE-2017-8641, CVE-2017-8645, CVE-2017-8646, CVE-2017-8647, CVE-2017-8655, CVE-2017-8657, CVE-2017-8670, CVE-2017-8671, CVE-2017-8672, and CVE-2017-8674.

    Source:Google Security Research
    Published:8 Aug 2017
    6.5
    Medium

    CVE-2017-8652

    Last Modified: 10 Aug 2017

    Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8662.

    Source:Google Security Research
    Published:8 Aug 2017