7.5
    High

    CVE-2017-7478

    Last Modified: 11 May 2017

    OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

    Source:QuarksLab
    Published:15 May 2017
    5.5
    Medium

    CVE-2017-7472

    Last Modified: 7 Jun 2017

    The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.

    Source:Marcus Meissner
    Published:1 Apr 2017
    9.8
    Critical

    CVE-2017-7462

    Last Modified: 7 Apr 2017

    Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.

    Source:Dimitri Fousekis
    Published:11 Apr 2017
    4.9
    Medium

    CVE-2017-7461

    Last Modified: 7 Apr 2017

    Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not do any URI/path sanitization.

    Source:Dimitri Fousekis
    Published:11 Apr 2017
    5
    Medium

    CVE-2017-7457

    Last Modified: 10 Apr 2017

    XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

    Source:hyp3rlinx
    Published:14 Apr 2017
    7.5
    High

    CVE-2017-7456

    Last Modified: 10 Apr 2017

    Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.

    Source:hyp3rlinx
    Published:14 Apr 2017
    7.5
    High

    CVE-2017-7455

    Last Modified: 10 Apr 2017

    Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.

    Source:hyp3rlinx
    Published:14 Apr 2017
    8.8
    High

    CVE-2017-7447

    Last Modified: 6 Apr 2017

    HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

    Source:rungga_reksya
    Published:5 Apr 2017
    8.8
    High

    CVE-2017-7446

    Last Modified: 6 Apr 2017

    HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.

    Source:rungga_reksya
    Published:5 Apr 2017
    8.8
    High

    CVE-2017-7442

    Last Modified: 2 Aug 2017

    Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.

    Source:Metasploit
    Published:3 Aug 2017
    8.8
    High

    CVE-2017-7411

    Last Modified: 19 Dec 2017

    An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks (including but not limited to Remote Code Execution).

    Source:Metasploit
    Published:30 Oct 2017
    9.8
    Critical

    CVE-2017-7410

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username, (2) display_name parameter.

    Published:3 Apr 2017
    9.8
    Critical

    CVE-2017-7402

    Last Modified: 4 Apr 2017

    Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.

    Source:rungga_reksya
    Published:3 Apr 2017
    8.8
    High

    CVE-2017-7398

    Last Modified: 5 Apr 2017

    D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin is currently authenticated, as demonstrated by changing the Security option from WPA2 to None, or changing the hiddenSSID parameter, SSID parameter, or a security-option password.

    Source:Pratik S. Shah
    Published:4 Apr 2017
    7.5
    High

    CVE-2017-7397

    Last Modified: 3 Apr 2017

    BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.

    Source:FarazPajohan
    Published:3 Apr 2017
    9.8
    Critical

    CVE-2017-7376

    Last Modified: 21 Nov 2024

    Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

    Published:17 Apr 2017
    7.8
    High

    CVE-2017-7374

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.

    Published:31 Mar 2017
    7.3
    High

    CVE-2017-7358

    Last Modified: 15 Feb 2018

    In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user logs out.

    Source:G. Geshev
    Published:5 Apr 2017
    7.5
    High

    CVE-2017-7314

    Last Modified: 3 Jul 2017

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.

    Source:Pesach Zirkind
    Published:7 Jun 2017
    9.8
    Critical

    CVE-2017-7312

    Last Modified: 3 Jul 2017

    An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).

    Source:Pesach Zirkind
    Published:7 Jun 2017
    7.8
    High

    CVE-2017-7310

    Last Modified: 25 Jan 2018

    A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary code via a crafted XML file containing a long name attribute of a classify element.

    Source:Metasploit
    Published:29 Mar 2017
    7.8
    High

    CVE-2017-7308

    Last Modified: 18 May 2018

    The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.

    Source:Metasploit
    Published:29 Mar 2017
    7.8
    High

    CVE-2017-7293

    Last Modified: 25 Apr 2017

    The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCOM. This affects Dolby Audio X2 (DAX2) 1.0, 1.0.1, 1.1, 1.1.1, 1.2, 1.3, 1.3.1, 1.3.2, 1.4, 1.4.1, 1.4.2, 1.4.3, and 1.4.4 and Dolby Audio X3 (DAX3) 1.0 and 1.1. An example affected driver is Realtek Audio Driver 6.0.1.7898 on a Lenovo P50.

    Source:Google Security Research
    Published:26 Apr 2017
    7.5
    High

    CVE-2017-7285

    Last Modified: 28 Mar 2017

    A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.

    Source:FarazPajohan
    Published:29 Mar 2017
    9.8
    Critical

    CVE-2017-7269

    Last Modified: 12 May 2017

    Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.

    Source:Metasploit
    Published:27 Mar 2017
    7.5
    High

    CVE-2017-7240

    Last Modified: 24 Mar 2017

    An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks. A Proof of Concept is GET /../../../../../../../../../../../../etc/shadow HTTP/1.1. This affects PG8527 devices 2.02 before 2.12, PG8527 devices 2.51 before 2.61, PG8527 devices 2.52 before 2.62, PG8527 devices 2.54 before 2.64, PG8528 devices 2.02 before 2.12, PG8528 devices 2.51 before 2.61, PG8528 devices 2.52 before 2.62, PG8528 devices 2.54 before 2.64, PG8535 devices 1.00 before 1.10, PG8535 devices 1.04 before 1.14, PG8536 devices 1.10 before 1.20, and PG8536 devices 1.14 before 1.24.

    Source:Jens Regel
    Published:24 Mar 2017
    9.8
    Critical

    CVE-2017-7237

    Last Modified: 6 Apr 2017

    The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69, as demonstrated by a WRQ (aka Write request) operation for a configuration file or an executable file.

    Source:hyp3rlinx
    Published:6 Apr 2017
    8.2
    High

    CVE-2017-7228

    Last Modified: 11 Apr 2017

    An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, allowing the caller to drive hypervisor memory accesses outside of the guest provided input/output arrays.

    Source:Google Security Research
    Published:4 Apr 2017
    8.8
    High

    CVE-2017-7221

    Last Modified: 25 Apr 2017

    OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase method with a user-created dm_procedure object, as demonstrated by use of a backspace character in an injected string. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2513.

    Source:Andrey B. Panfilov
    Published:25 Apr 2017
    5.4
    Medium

    CVE-2017-7188

    Last Modified: 20 Apr 2025

    Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.

    Published:14 Apr 2017
    7.5
    High

    CVE-2017-7185

    Last Modified: 6 Apr 2017

    Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.

    Source:Compass Security
    Published:10 Apr 2017
    7.8
    High

    CVE-2017-7184

    Last Modified: 20 Apr 2025

    The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain size data after an XFRM_MSG_NEWAE update, which allows local users to obtain root privileges or cause a denial of service (heap-based out-of-bounds access) by leveraging the CAP_NET_ADMIN capability, as demonstrated during a Pwn2Own competition at CanSecWest 2017 for the Ubuntu 16.10 linux-image-* package 4.8.0.41.52.

    Published:19 Mar 2017
    7.5
    High

    CVE-2017-7183

    Last Modified: 20 Mar 2017

    The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.

    Source:hyp3rlinx
    Published:27 Mar 2017
    7.3
    High

    CVE-2017-7180

    Last Modified: 8 Jun 2017

    Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, such as the %SYSTEMDRIVE% directory, and thus the issue is not interpreted as a direct privilege escalation. However, the local attacker might have the goal of executing program.exe even though program.exe is a blocked application.

    Source:Saeid Atabaki
    Published:8 Jun 2017
    8.8
    High

    CVE-2017-7178

    Last Modified: 6 Mar 2017

    CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

    Source:Kyle Neideck
    Published:18 Mar 2017
    9.9
    Critical

    CVE-2017-7175

    Last Modified: 11 Jul 2017

    NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).

    Source:Paul Taylor
    Published:10 Jul 2017
    5.5
    Medium

    CVE-2017-7173

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Published:3 Apr 2018
    6.6
    Medium

    CVE-2017-7154

    Last Modified: 11 Jan 2018

    An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS before 11.2 is affected. The issue involves the "Kernel" component. It allows local users to bypass intended memory-read restrictions or cause a denial of service (system crash).

    Source:Google Security Research
    Published:25 Dec 2017
    8.8
    High

    CVE-2017-7117

    Last Modified: 4 Oct 2017

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:23 Oct 2017
    8.1
    High

    CVE-2017-7115

    Last Modified: 17 Oct 2017

    An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via crafted Wi-Fi traffic that leverages a race condition.

    Source:Google Security Research
    Published:23 Oct 2017
    8.8
    High

    CVE-2017-7092

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published:23 Oct 2017
    6.1
    Medium

    CVE-2017-7089

    Last Modified: 15 Nov 2018

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that is mishandled during parent-tab processing.

    Source:Anton Lopanitsyn
    Published:23 Oct 2017
    5.5
    Medium

    CVE-2017-7064

    Last Modified: 25 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. The issue involves the "WebKit" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7061

    Last Modified: 12 Sept 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7056

    Last Modified: 25 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7049

    Last Modified: 24 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7048

    Last Modified: 24 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7047

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is affected. The issue involves the "libxpc" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7046

    Last Modified: 24 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017
    8.8
    High

    CVE-2017-7043

    Last Modified: 24 Jul 2017

    An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:20 Jul 2017