5.3
    Medium

    CVE-2017-6020

    Last Modified: 28 Sept 2017

    Leao Consultoria e Desenvolvimento de Sistemas (LCDS) LTDA ME LAquis SCADA software versions prior to version 4.1.0.3237 do not neutralize external input to ensure that users are not calling for absolute path sequences outside of their privilege level.

    Source:James Fitts
    Published:17 Apr 2018
    7.5
    High

    CVE-2017-6019

    Last Modified: 6 Mar 2017

    An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.

    Source:Mark Liapustin & Arik Kublanov
    Published:7 Apr 2017
    7.8
    High

    CVE-2017-6008

    Last Modified: 26 Oct 2017

    A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.

    Source:cbayet
    Published:13 Sept 2017
    7.5
    High

    CVE-2017-5991

    Last Modified: 7 Jun 2017

    An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.

    Source:Kamil Frankowicz
    Published:15 Feb 2017
    7.5
    High

    CVE-2017-5972

    Last Modified: 7 Mar 2019

    The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship between the GitHub Engineering finding and the Trigemini.c attack code.

    Source:FarazPajohan
    Published:12 Feb 2017
    9.8
    Critical

    CVE-2017-5941

    Last Modified: 27 Aug 2018

    An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).

    Source:OpSecX
    Published:9 Feb 2017
    9.8
    Critical

    CVE-2017-5929

    Last Modified: 20 Apr 2025

    QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

    Published:8 Feb 2017
    7
    High

    CVE-2017-5899

    Last Modified: 26 Jul 2019

    Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.

    Source:bcoles
    Published:27 Jan 2017
    7.8
    High

    CVE-2017-5881

    Last Modified: 15 Feb 2017

    GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.

    Source:Peter Baris
    Published:21 Feb 2017
    5.4
    Medium

    CVE-2017-5871

    Last Modified: 21 Nov 2024

    Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).

    Published:22 May 2019
    8.8
    High

    CVE-2017-5869

    Last Modified: 27 Mar 2017

    Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote authenticated users to upload and execute arbitrary JSP code via a .. (dot dot) in the X-File-Name header.

    Source:Sysdream
    Published:24 Mar 2017
    7.5
    High

    CVE-2017-5850

    Last Modified: 7 Feb 2017

    httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.

    Source:PierreKimSec
    Published:27 Mar 2017
    9.8
    Critical

    CVE-2017-5817

    Last Modified: 10 Jan 2018

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Source:Chris Lyne
    Published:15 Feb 2018
    9.8
    Critical

    CVE-2017-5816

    Last Modified: 10 Jan 2018

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Source:Chris Lyne
    Published:15 Feb 2018
    9.8
    Critical

    CVE-2017-5815

    Last Modified: 15 Feb 2018

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.

    Source:SecuriTeam
    Published:15 Feb 2018
    8.8
    High

    CVE-2017-5799

    Last Modified: 25 Apr 2017

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

    Source:Paolo Stagno
    Published:15 Feb 2018
    6.1
    Medium

    CVE-2017-5798

    Last Modified: 25 Apr 2017

    A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP versions prior to 3.4.2 RP201 (for OCMP 3.x), all versions prior to 4.4.7 RP702 (for OCMP 4.x).

    Source:Paolo Stagno
    Published:15 Feb 2018
    9.8
    Critical

    CVE-2017-5792

    Last Modified: 30 Jan 2018

    A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.

    Source:Chris Lyne
    Published:15 Feb 2018
    5.6
    Medium

    CVE-2017-5754

    Last Modified: 28 May 2026

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

    Published:3 Jan 2018
    5.6
    Medium

    CVE-2017-5753

    Last Modified: 5 Jan 2018

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Source:Multiple
    Published:3 Jan 2018
    7.5
    High

    CVE-2017-5721

    Last Modified: 20 Apr 2025

    Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.

    Published:11 Oct 2017
    7.8
    High

    CVE-2017-5717

    Last Modified: 19 Dec 2017

    Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.

    Source:Google Security Research
    Published:12 Dec 2017
    5.6
    Medium

    CVE-2017-5715

    Last Modified: 5 Jan 2018

    Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

    Source:Multiple
    Published:3 Jan 2018
    7.5
    High

    CVE-2017-5693

    Last Modified: 21 Nov 2024

    Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network attacker to create a denial of service via crafted network traffic.

    Published:31 Jul 2018
    9.8
    Critical

    CVE-2017-5689

    Last Modified: 8 Jan 2018

    An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

    Source:nixawk
    Published:2 May 2017
    8.8
    High

    CVE-2017-5671

    Last Modified: 28 Mar 2017

    Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, which allows local users to conduct a BusyBox jailbreak attack and obtain root privileges by overwriting the /etc/shadow file.

    Source:Jean-Marie Bourbon
    Published:29 Mar 2017
    9.8
    Critical

    CVE-2017-5645

    Last Modified: 20 Apr 2025

    In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

    Published:2 Apr 2017
    9.8
    Critical

    CVE-2017-5638

    Last Modified: 11 Sept 2018

    The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.

    Source:Vex Woo
    Published:6 Mar 2017
    7.5
    High

    CVE-2017-5637

    Last Modified: 4 Oct 2017

    Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffer from this issue, fixed in 3.4.10, 3.5.3, and later.

    Source:Brandon Dennis
    Published:7 Feb 2017
    8
    High

    CVE-2017-5633

    Last Modified: 14 Mar 2017

    Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow remote attackers to (1) change the admin password, (2) reboot the device, or (3) possibly have unspecified other impact via crafted requests to CGI programs.

    Source:Felipe Soares de Souza
    Published:6 Mar 2017
    6.1
    Medium

    CVE-2017-5631

    Last Modified: 21 May 2017

    An issue was discovered in KMCIS CaseAware. Reflected cross site scripting is present in the user parameter (i.e., "usr") that is transmitted in the login.php query string.

    Source:justpentest
    Published:1 May 2017
    7.5
    High

    CVE-2017-5630

    Last Modified: 30 Jan 2017

    PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenames after a redirect, which allows remote HTTP servers to overwrite files via crafted responses, as demonstrated by a .htaccess overwrite.

    Source:hyp3rlinx
    Published:26 Jan 2017
    7.8
    High

    CVE-2017-5618

    Last Modified: 20 Apr 2025

    GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.

    Published:24 Jan 2017
    3.5
    Low

    CVE-2017-5607

    Last Modified: 31 Mar 2017

    Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.

    Source:hyp3rlinx
    Published:10 Apr 2017
    7.5
    High

    CVE-2017-5594

    Last Modified: 22 Jan 2017

    An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

    Source:Saurabh Banawar
    Published:25 Jan 2017
    9.8
    Critical

    CVE-2017-5586

    Last Modified: 15 Feb 2017

    OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the BeanShell (bsh) and Apache Commons Collections (ACC) libraries.

    Source:Andrey B. Panfilov
    Published:22 Feb 2017
    8.1
    High

    CVE-2017-5521

    Last Modified: 1 Feb 2017

    An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R6700, R6900, and R8000 devices. They are prone to password disclosure via simple crafted requests to the web management server. The bug is exploitable remotely if the remote management option is set, and can also be exploited given access to the router over LAN or WLAN. When trying to access the web panel, a user is asked to authenticate; if the authentication is canceled and password recovery is not enabled, the user is redirected to a page that exposes a password recovery token. If a user supplies the correct token to the page /passwordrecovered.cgi?id=TOKEN (and password recovery is not enabled), they will receive the admin password for the router. If password recovery is set the exploit will fail, as it will ask the user for the recovery questions that were previously set when enabling that feature. This is persistent (even after disabling the recovery option, the exploit will fail) because the router will ask for the security questions.

    Source:Trustwave's SpiderLabs
    Published:17 Jan 2017
    9.8
    Critical

    CVE-2017-5496

    Last Modified: 19 Feb 2017

    Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.

    Source:hyp3rlinx
    Published:15 Mar 2017
    5.3
    Medium

    CVE-2017-5487

    Last Modified: 4 May 2017

    wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly restrict listings of post authors, which allows remote attackers to obtain sensitive information via a wp-json/wp/v2/users request.

    Source:Dctor
    Published:15 Jan 2017
    8.8
    High

    CVE-2017-5473

    Last Modified: 30 Jan 2017

    Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authentication of arbitrary users, as demonstrated by admin/add_user.lua, admin/change_user_prefs.lua, admin/delete_user.lua, and admin/password_reset.lua.

    Source:hyp3rlinx
    Published:14 Jan 2017
    9.1
    Critical

    CVE-2017-5465

    Last Modified: 25 May 2017

    An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

    Source:Google Security Research
    Published:19 Apr 2017
    9.1
    Critical

    CVE-2017-5447

    Last Modified: 25 May 2017

    An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

    Source:Google Security Research
    Published:19 Apr 2017
    5.3
    Medium

    CVE-2017-5415

    Last Modified: 9 Mar 2018

    An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.

    Source:649
    Published:11 Jun 2018
    9.8
    Critical

    CVE-2017-5404

    Last Modified: 20 Mar 2017

    A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

    Source:Google Security Research
    Published:7 Mar 2017
    9.8
    Critical

    CVE-2017-5375

    Last Modified: 20 Mar 2018

    JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

    Source:Rh0
    Published:24 Jan 2017
    7.5
    High

    CVE-2017-5359

    Last Modified: 22 Feb 2017

    EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.

    Source:hyp3rlinx
    Published:15 Mar 2017
    9.8
    Critical

    CVE-2017-5358

    Last Modified: 22 Feb 2017

    Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.

    Source:hyp3rlinx
    Published:15 Mar 2017
    9.8
    Critical

    CVE-2017-5344

    Last Modified: 16 Feb 2017

    An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.

    Source:Ben Nott
    Published:17 Feb 2017
    7.8
    High

    CVE-2017-5329

    Last Modified: 27 Jan 2017

    Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.

    Source:Parvez Anwar
    Published:27 Jan 2017
    8.8
    High

    CVE-2017-5264

    Last Modified: 28 Jan 2018

    Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.

    Source:Shwetabh Vishnoi
    Published:14 Dec 2017