9.8
    Critical

    CVE-2017-6506

    Last Modified: 7 Mar 2017

    In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.

    Source:Peter Baris
    Published:10 Mar 2017
    6.1
    Medium

    CVE-2017-6478

    Last Modified: 3 Dec 2025

    paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).

    Source:CodeSecLab
    Published:5 Mar 2017
    9.8
    Critical

    CVE-2017-6465

    Last Modified: 6 Mar 2017

    Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting to; however, it doesn't check the response's length, leading to a buffer overflow situation.

    Source:Peter Baris
    Published:10 Mar 2017
    7.5
    High

    CVE-2017-6444

    Last Modified: 7 Mar 2019

    The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation.

    Source:FarazPajohan
    Published:12 Mar 2017
    6.1
    Medium

    CVE-2017-6443

    Last Modified: 5 Mar 2017

    Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.

    Source:Michael Benich
    Published:15 Mar 2017
    7.5
    High

    CVE-2017-6427

    Last Modified: 25 Apr 2017

    A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will cause a crash. An example attack methodology may include a long message-body in a GET request.

    Source:Peter Baris
    Published:10 Mar 2017
    8.1
    High

    CVE-2017-6412

    Last Modified: 18 Jul 2017

    In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.

    Source:SlidingWindow
    Published:30 Mar 2017
    8.8
    High

    CVE-2017-6411

    Last Modified: 1 Mar 2017

    Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.

    Source:B GOVIND
    Published:6 Mar 2017
    7.5
    High

    CVE-2017-6371

    Last Modified: 28 Feb 2017

    Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.

    Source:Peter Baris
    Published:27 Feb 2020
    5.3
    Medium

    CVE-2017-6370

    Last Modified: 20 Apr 2025

    TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitive cleartext information by sniffing the network and reading the userident and username fields.

    Published:17 Mar 2017
    7.5
    High

    CVE-2017-6367

    Last Modified: 13 Mar 2017

    In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.

    Source:Peter Baris
    Published:14 Mar 2017
    8.8
    High

    CVE-2017-6366

    Last Modified: 28 Feb 2017

    Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslookup.cgi. NOTE: this issue can be combined with CVE-2017-6334 to execute arbitrary code remotely.

    Source:SivertPL
    Published:15 Mar 2017
    9.8
    Critical

    CVE-2017-6361

    Last Modified: 7 Apr 2017

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.

    Source:Harry Sintonen
    Published:23 Mar 2017
    9.8
    Critical

    CVE-2017-6360

    Last Modified: 7 Apr 2017

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.

    Source:Harry Sintonen
    Published:23 Mar 2017
    9.8
    Critical

    CVE-2017-6359

    Last Modified: 7 Apr 2017

    QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.

    Source:Harry Sintonen
    Published:23 Mar 2017
    8.1
    High

    CVE-2017-6351

    Last Modified: 1 Mar 2017

    The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet protocol and log into the device with the 'abarco' hardcoded manufacturer account. This account is not documented, nor is the DEBUG feature or the use of telnetd on port tcp/5885.

    Source:Quentin Olagne
    Published:6 Mar 2017
    5.4
    Medium

    CVE-2017-6340

    Last Modified: 16 May 2017

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/report/template name field, which allows a 'Reports Only' user to inject malicious JavaScript while creating a new report. Additionally, IWSVA implements incorrect access control that allows any authenticated, remote user (even with low privileges like 'Auditor') to create or modify reports, and consequently take advantage of this XSS vulnerability. The JavaScript is executed when victims visit reports or auditlog pages.

    Source:SlidingWindow
    Published:5 Apr 2017
    6.5
    Medium

    CVE-2017-6339

    Last Modified: 16 May 2017

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to client browsers to complete a secure passage for HTTPS connections. It also allows administrators to upload their own certificates signed by a root CA. An attacker with low privileges can download the current CA certificate and Private Key (either the default ones or ones uploaded by administrators) and use those to decrypt HTTPS traffic, thus compromising confidentiality. Also, the default Private Key on this appliance is encrypted with a very weak passphrase. If an appliance uses the default Certificate and Private Key provided by Trend Micro, an attacker can simply download these and decrypt the Private Key using the default/weak passphrase.

    Source:SlidingWindow
    Published:5 Apr 2017
    6.5
    Medium

    CVE-2017-6338

    Last Modified: 16 May 2017

    Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload an HTTPS Decryption Certificate and Private Key.

    Source:SlidingWindow
    Published:5 Apr 2017
    8.8
    High

    CVE-2017-6334

    Last Modified: 26 Jun 2017

    dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability than CVE-2017-6077.

    Source:Metasploit
    Published:6 Mar 2017
    7.1
    High

    CVE-2017-6331

    Last Modified: 14 Nov 2017

    Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a type of attack that bypasses the real time protection for the application that is run on servers and clients.

    Source:hyp3rlinx
    Published:6 Nov 2017
    8.8
    High

    CVE-2017-6328

    Last Modified: 4 Sept 2017

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one-click attack and is abbreviated as CSRF or XSRF), which is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the web application trusts. A CSRF attack attempts to exploit the trust that a specific website has in a user's browser.

    Source:Dhiraj Mishra
    Published:11 Aug 2017
    8.8
    High

    CVE-2017-6327

    Last Modified: 18 Aug 2017

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process. In this type of occurrence, after gaining access to the system, the attacker may attempt to elevate their privileges.

    Source:Philip Pettersson
    Published:11 Aug 2017
    10
    Critical

    CVE-2017-6326

    Last Modified: 26 Jun 2017

    The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an individual may obtain the ability to execute commands remotely on a target machine or in a target process.

    Source:Mehmet Ince
    Published:26 Jun 2017
    8.8
    High

    CVE-2017-6320

    Last Modified: 19 Jul 2017

    A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (2015-11-26) and v6.0.1.006 (2016-08-19); fixed in 6.1.0.003 (2017-01-17)) in which an authenticated user can execute arbitrary shell commands and gain root privileges. The vulnerability stems from unsanitized data being processed in a system call when the delete_assessment command is issued.

    Source:xort
    Published:18 Jul 2017
    9.8
    Critical

    CVE-2017-6316

    Last Modified: 19 Jul 2017

    Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as root via a CGISESSID cookie. On CloudBridge (the former name of NetScaler SD-WAN) devices, the cookie name was CAKEPHP rather than CGISESSID.

    Source:xort
    Published:20 Jul 2017
    9.8
    Critical

    CVE-2017-6315

    Last Modified: 15 Sept 2017

    Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx.

    Source:Jakub Palaczynski
    Published:19 Sept 2017
    7.5
    High

    CVE-2017-6206

    Last Modified: 20 Mar 2017

    D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Information Disclosure attacks via unspecified vectors.

    Source:Varang Amin
    Published:23 Feb 2017
    5.5
    Medium

    CVE-2017-6193

    Last Modified: 20 Apr 2017

    Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted image containing a malformed image size descriptor in the IHDR chunk.

    Source:Alwin Peppels
    Published:20 Feb 2018
    5.5
    Medium

    CVE-2017-6192

    Last Modified: 20 Apr 2017

    Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted image containing a malformed chunk size descriptor.

    Source:Alwin Peppels
    Published:20 Feb 2018
    7.8
    High

    CVE-2017-6191

    Last Modified: 22 Mar 2017

    Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.

    Source:Alwin Peppels
    Published:23 Mar 2017
    7.5
    High

    CVE-2017-6190

    Last Modified: 12 Apr 2017

    Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.

    Source:Patryk Bogdan
    Published:10 Apr 2017
    9.8
    Critical

    CVE-2017-6187

    Last Modified: 22 Feb 2017

    Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.

    Source:Peter Baris
    Published:22 Feb 2017
    9.8
    Critical

    CVE-2017-6182

    Last Modified: 18 Jul 2017

    In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.

    Source:xort
    Published:30 Mar 2017
    7.8
    High

    CVE-2017-6178

    Last Modified: 15 Mar 2017

    The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.

    Source:Parvez Anwar
    Published:20 Mar 2017
    7.5
    High

    CVE-2017-6104

    Last Modified: 6 Mar 2017

    Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

    Source:The Martian
    Published:2 Mar 2017
    7.2
    High

    CVE-2017-6098

    Last Modified: 24 Feb 2017

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.

    Source:Hanley Shun
    Published:21 Feb 2017
    7.2
    High

    CVE-2017-6097

    Last Modified: 24 Feb 2017

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.

    Source:Hanley Shun
    Published:21 Feb 2017
    7.2
    High

    CVE-2017-6096

    Last Modified: 24 Feb 2017

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.

    Source:Hanley Shun
    Published:21 Feb 2017
    9.8
    Critical

    CVE-2017-6095

    Last Modified: 24 Feb 2017

    A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.

    Source:Hanley Shun
    Published:21 Feb 2017
    8.8
    High

    CVE-2017-6090

    Last Modified: 11 Jan 2018

    Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.

    Source:Metasploit
    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-6089

    Last Modified: 2 Oct 2017

    SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php; the (2) id parameter to bookmarks/deletebookmarks.php; or the (3) id parameter to calendar/deletecalendar.php.

    Source:Sysdream
    Published:2 Oct 2017
    7.2
    High

    CVE-2017-6088

    Last Modified: 27 Mar 2017

    Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (4) equipment parameter to module/monitoring_ged/ged_functions.php or the (5) type parameter to monitoring_ged/ajax.php.

    Source:Sysdream
    Published:11 Apr 2017
    8.8
    High

    CVE-2017-6087

    Last Modified: 27 Mar 2017

    EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the selected_events[] parameter in the (1) acknowledge, (2) delete, or (3) ownDisown function in module/monitoring_ged/ged_functions.php or the (4) module parameter to module/index.php.

    Source:Sysdream
    Published:24 Mar 2017
    8.8
    High

    CVE-2017-6086

    Last Modified: 5 May 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities in the addAction and purgeAction functions in ViMbAdmin 3.0.15 allow remote attackers to hijack the authentication of logged administrators to (1) add an administrator user via a crafted POST request to <vimbadmin directory>/application/controllers/DomainController.php, (2) remove an administrator user via a crafted GET request to <vimbadmin directory>/application/controllers/DomainController.php, (3) change an administrator password via a crafted POST request to <vimbadmin directory>/application/controllers/DomainController.php, (4) add a mailbox via a crafted POST request to <vimbadmin directory>/application/controllers/MailboxController.php, (5) delete a mailbox via a crafted POST request to <vimbadmin directory>/application/controllers/MailboxController.php, (6) archive a mailbox address via a crafted GET request to <vimbadmin directory>/application/controllers/ArchiveController.php, (7) add an alias address via a crafted POST request to <vimbadmin directory>/application/controllers/AliasController.php, or (8) remove an alias address via a crafted GET request to <vimbadmin directory>/application/controllers/AliasController.php.

    Source:Sysdream
    Published:27 Jun 2017
    9.8
    Critical

    CVE-2017-6079

    Last Modified: 20 Apr 2025

    The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such as specific iptables routes, etc., to be set. You can use this page as a web shell essentially to execute commands, though you get no feedback client-side from the web application: if the command is valid, it executes. An example is the wget command. The page that allows this has been confirmed in firmware as old as 2006.

    Published:16 May 2017
    9.8
    Critical

    CVE-2017-6077

    Last Modified: 19 Feb 2017

    ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.

    Source:SivertPL
    Published:22 Feb 2017
    7.8
    High

    CVE-2017-6074

    Last Modified: 6 Mar 2017

    The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

    Source:Andrey Konovalov
    Published:18 Feb 2017
    7.8
    High

    CVE-2017-6060

    Last Modified: 7 Jun 2017

    Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.

    Source:Agostino Sarubbo
    Published:15 Mar 2017
    9.1
    Critical

    CVE-2017-6026

    Last Modified: 30 Nov 2018

    A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware versions prior to Version 4.0.5.11, and Modicon M251, firmware versions prior to Version 4.0.5.11. The session numbers generated by the web application are lacking randomization and are shared between several users. This may allow a current session to be compromised.

    Source:Photubias
    Published:30 Jun 2017