LiveActive security incident?Get immediate response
CVE archive

February 2017

Browse CVE records published in February 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 872 matching CVEs · Page 6 of 18.

Unknown · CVSS Not scored

CVE-2017-13233: In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion.

In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote temporary denial of service with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-62851602.

Published Feb 12, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-18034: The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows r...

The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attackers that have write access to an indexed repository to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in via a specially crafted repository branch name when trying to display deleted files of the branch.

Published Feb 2, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-2293: Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that...

Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the package plugin to install or remove arbitrary packages on all managed agents. This release adds default configuration to not allow these actions. Customers who rely on this functionality can change this policy.

Published Feb 1, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-18196: Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on...

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

Published Feb 23, 2018 · Updated Sep 16, 2024

Low · CVSS 3.7

CVE-2017-1200: IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates,...

IBM BigFix Compliance 1.7 through 1.9.91 (TEMA SUAv1 SCA SCM) does not validate, or incorrectly validates, a certificate.This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host. IBM X-Force ID: 123675.

Published Feb 5, 2019 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-1758: IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM...

IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3, 3.0.4, and 3.1.0, IBM Transformation Extender Advanced 9.0) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 135859.

Published Feb 21, 2018 · Updated Sep 16, 2024

Low · CVSS 3.1

CVE-2017-20178: Codiad process.php saveJSON information disclosure

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Codiad 2.8.0. It has been rated as problematic. Affected by this issue is the function saveJSON of the file components/install/process.php. The manipulation of the argument data leads to information disclosure. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 2.8.1 is able to address this issue. The patch is identified as 517119de673e62547ee472a730be0604f44342b5. It is recommended to upgrade the affected component. VDB-221498 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Published Feb 21, 2023 · Updated Aug 5, 2024

Medium · CVSS 6.5

CVE-2017-20179: InSTEDD Pollit tour_controller.rb TourController Privilege Escalation

A vulnerability was found in InSTEDD Pollit 2.3.1. It has been rated as critical. This issue affects the function TourController of the file app/controllers/tour_controller.rb. The manipulation leads to an unknown weakness. The attack may be initiated remotely. Upgrading to version 2.3.2 is able to address this issue. The patch is named 6ef04f8b5972d5f16f8b86f8b53f62fac68d5498. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-221507.

Published Feb 21, 2023 · Updated Aug 5, 2024