6.1
    Medium

    CVE-2017-3133

    Last Modified: 30 Apr 2021

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.

    Source:patryk_bogdan
    Published:12 Sept 2017
    6.1
    Medium

    CVE-2017-3132

    Last Modified: 30 Apr 2021

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the action input during the activation of a FortiToken.

    Source:patryk_bogdan
    Published:12 Sept 2017
    5.4
    Medium

    CVE-2017-3131

    Last Modified: 30 Apr 2021

    A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or commands via the filter input in "Applications" under FortiView.

    Source:patryk_bogdan
    Published:12 Sept 2017
    8.8
    High

    CVE-2017-3106

    Last Modified: 17 Aug 2017

    Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:8 Aug 2017
    9.8
    Critical

    CVE-2017-3078

    Last Modified: 23 Jun 2017

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:13 Jun 2017
    9.8
    Critical

    CVE-2017-3077

    Last Modified: 23 Jun 2017

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:13 Jun 2017
    9.8
    Critical

    CVE-2017-3076

    Last Modified: 23 Jun 2017

    Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:13 Jun 2017
    8.8
    High

    CVE-2017-3068

    Last Modified: 17 May 2017

    Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:9 May 2017
    9.8
    Critical

    CVE-2017-3066

    Last Modified: 7 Feb 2018

    Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

    Source:Faisal Tameesh
    Published:27 Apr 2017
    7.8
    High

    CVE-2017-3064

    Last Modified: 17 May 2017

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:11 Apr 2017
    9.8
    Critical

    CVE-2017-3061

    Last Modified: 17 May 2017

    Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:11 Apr 2017
    8.8
    High

    CVE-2017-3006

    Last Modified: 14 Apr 2017

    Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.

    Source:hyp3rlinx
    Published:12 Apr 2017
    6.5
    Medium

    CVE-2017-3000

    Last Modified: 20 Apr 2025

    Adobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding. Successful exploitation could lead to information disclosure.

    Published:14 Mar 2017
    8.8
    High

    CVE-2017-2992

    Last Modified: 21 Feb 2017

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 header. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:14 Feb 2017
    8.8
    High

    CVE-2017-2988

    Last Modified: 21 Feb 2017

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing garbage collection. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:14 Feb 2017
    8.8
    High

    CVE-2017-2986

    Last Modified: 21 Feb 2017

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:14 Feb 2017
    8.8
    High

    CVE-2017-2985

    Last Modified: 21 Feb 2017

    Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript 3 BitmapData class. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:14 Feb 2017
    8.8
    High

    CVE-2017-2935

    Last Modified: 15 Mar 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Jan 2017
    8.8
    High

    CVE-2017-2934

    Last Modified: 15 Mar 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Jan 2017
    8.8
    High

    CVE-2017-2933

    Last Modified: 15 Mar 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Jan 2017
    8.8
    High

    CVE-2017-2932

    Last Modified: 15 Mar 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript MovieClip class. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Jan 2017
    8.8
    High

    CVE-2017-2931

    Last Modified: 15 Mar 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the parsing of SWF metadata. Successful exploitation could lead to arbitrary code execution.

    Source:Google Security Research
    Published:10 Jan 2017
    8.8
    High

    CVE-2017-2930

    Last Modified: 12 Jan 2017

    Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurrency error when manipulating a display list. Successful exploitation could lead to arbitrary code execution.

    Source:COSIG
    Published:10 Jan 2017
    7.8
    High

    CVE-2017-2903

    Last Modified: 21 Nov 2024

    An exploitable integer overflow exists in the DPX loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.cin' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.

    Published:24 Apr 2018
    8.1
    High

    CVE-2017-2824

    Last Modified: 20 Apr 2025

    An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this vulnerability.

    Published:24 May 2017
    9.8
    Critical

    CVE-2017-2800

    Last Modified: 9 May 2017

    A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and possible remote code execution. In order to trigger this vulnerability, the attacker needs to supply a malicious x509 certificate to either a server or a client application using this library.

    Source:Talos
    Published:24 May 2017
    Unknown

    CVE-2017-2796

    https://www.exploit-db.com/exploits/44063

    8.3
    High

    CVE-2017-2793

    Last Modified: 20 Apr 2025

    An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilter used by MarkLogic 8.0-6. A specially crafted xls file can cause a heap corruption resulting in arbitrary code execution. An attacker can send/provide malicious XLS file to trigger this vulnerability.

    Published:23 May 2017
    4.6
    Medium

    CVE-2017-2751

    Last Modified: 21 Nov 2024

    A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. The BIOS password was stored in CMOS in a way that allowed it to be extracted. This applies to consumer notebooks launched in early 2014.

    Published:3 Oct 2018
    9.8
    Critical

    CVE-2017-2741

    Last Modified: 14 Jun 2017

    A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmware before 1708D. This vulnerability could potentially be exploited to execute arbitrary code.

    Source:Jacob Baines
    Published:23 Jan 2018
    5.5
    Medium

    CVE-2017-2671

    Last Modified: 7 Mar 2019

    The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.

    Source:Daniel Jiang
    Published:24 Mar 2017
    6.5
    Medium

    CVE-2017-2666

    Last Modified: 21 Nov 2024

    It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

    Published:7 Jun 2017
    8.1
    High

    CVE-2017-2649

    Last Modified: 21 Nov 2024

    It was found that the Active Directory Plugin for Jenkins up to and including version 2.2 did not verify certificates of the Active Directory server, thereby enabling Man-in-the-Middle attacks.

    Published:27 Jul 2018
    9.8
    Critical

    CVE-2017-2641

    Last Modified: 6 Apr 2017

    In Moodle 2.x and 3.x, SQL injection can occur via user preferences.

    Source:Marko Belzetski
    Published:26 Mar 2017
    7
    High

    CVE-2017-2636

    Last Modified: 20 Apr 2025

    Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.

    Published:7 Mar 2017
    7.5
    High

    CVE-2017-2619

    Last Modified: 27 Mar 2017

    Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.

    Source:Google Security Research
    Published:23 Mar 2017
    8.8
    High

    CVE-2017-2547

    Last Modified: 16 Jun 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:22 May 2017
    8.8
    High

    CVE-2017-2536

    Last Modified: 6 Jun 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:saelo
    Published:22 May 2017
    7
    High

    CVE-2017-2533

    Last Modified: 9 Jun 2017

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitration" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:phoenhex
    Published:22 May 2017
    8.8
    High

    CVE-2017-2531

    Last Modified: 1 Jun 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:22 May 2017
    6.1
    Medium

    CVE-2017-2528

    Last Modified: 1 Jun 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with cached frames.

    Source:Google Security Research
    Published:22 May 2017
    9.8
    Critical

    CVE-2017-2527

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory consumption and application crash) via crafted data.

    Source:Google Security Research
    Published:22 May 2017
    9.8
    Critical

    CVE-2017-2524

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "TextInput" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.

    Source:Google Security Research
    Published:22 May 2017
    9.8
    Critical

    CVE-2017-2523

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.

    Source:Google Security Research
    Published:22 May 2017
    9.8
    Critical

    CVE-2017-2522

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted data.

    Source:Google Security Research
    Published:22 May 2017
    8.8
    High

    CVE-2017-2521

    Last Modified: 1 Jun 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:22 May 2017
    5
    Medium

    CVE-2017-2516

    Last Modified: 22 May 2017

    An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" component. It allows attackers to bypass intended memory-read restrictions via a crafted app.

    Source:Google Security Research
    Published:22 May 2017
    8.8
    High

    CVE-2017-2515

    Last Modified: 25 May 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS before 10.2.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:22 May 2017
    8.8
    High

    CVE-2017-2514

    Last Modified: 25 May 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Source:Google Security Research
    Published:22 May 2017
    6.1
    Medium

    CVE-2017-2510

    Last Modified: 25 May 2017

    An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted web site that improperly interacts with pageshow events.

    Source:Google Security Research
    Published:22 May 2017