LiveActive security incident?Get immediate response
CVE archive

April 2017

Browse CVE records published in April 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1628 matching CVEs · Page 8 of 33.

Unknown · CVSS Not scored

CVE-2017-6323: The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issu...

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

Published Apr 16, 2018 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2017-2839: An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2...

An exploitable denial of service vulnerability exists within the handling of challenge packets in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-2825: In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database...

In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

Published Apr 20, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2017-2861: An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream...

An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out of bounds read resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

Published Apr 5, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-14458: An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF R...

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 8.3.2.25013. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execution. An attacker needs to trick the user to open the malicious file to trigger this vulnerability. If the browser plugin extension is enabled, visiting a malicious site can also trigger the vulnerability.

Published Apr 23, 2018 · Updated Sep 16, 2024

Medium · CVSS 6.1

CVE-2017-1772: IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scri...

IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136786.

Published Apr 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-1724: IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting.

IBM Security QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134814.

Published Apr 26, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13289: In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size...

In writeToParcel and createFromParcel of RttManager.java, there is a permission bypass due to a write size mismatch. This could lead to a local escalation of privileges where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70398564.

Published Apr 4, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-2907: An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d...

An exploitable integer overflow exists in the animation playing functionality of the Blender open-source 3d creation suite version 2.78c. A specially created '.avi' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset in order to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-2905: An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creat...

An exploitable integer overflow exists in the bmp loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.bmp' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13248: In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a mis...

In impeg2_idct_recon_sse42() of impeg2_idct_recon_sse42_intr.c, there is an out of bound write due to a missing bounds check. This could lead to an remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70349612.

Published Apr 4, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-12101: An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blend...

An exploitable integer overflow exists in the 'modifier_mdef_compact_influences' functionality of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open a .blend file in order to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-2904: An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d...

An exploitable integer overflow exists in the RADIANCE loading functionality of the Blender open-source 3d creation suite version 2.78c. A specially crafted '.hdr' file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to use the file as an asset via the sequencer in order to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

High · CVSS 7.7

CVE-2017-12090: An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen B...

An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flashing snmp-set commands, can cause a device power cycle resulting in downtime for the device. An attacker can send one packet to trigger this vulnerability.

Published Apr 5, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-18074: In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9607...

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 800, SD 808, SD 810, SD 820, SD 835, while playing a .wma file with modified media header with non-standard bytes per second parameter value, a reachable assert occurs.

Published Apr 11, 2018 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2017-2837: An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0...

An exploitable denial of service vulnerability exists within the handling of security data in FreeRDP 2.0.0-beta1+android11. A specially crafted challenge packet can cause the program termination leading to a denial of service condition. An attacker can compromise the server or use man in the middle to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13267: In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds ch...

In avrc_pars_vendor_cmd of avrc_pars_tg.cc, there is a possible stack corruption due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69479009.

Published Apr 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13290: In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds ch...

In sdp_server_handle_client_req of sdp_server.cc, there is an out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-69384124.

Published Apr 4, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-12104: An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c dra...

An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.

Published Apr 24, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-1725: IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM...

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) contain an undisclosed vulnerability with the potential for information disclosure. IBM X-Force ID: 134820.

Published Apr 24, 2018 · Updated Sep 16, 2024

Critical · CVSS 10

CVE-2017-14464: An exploitable access control vulnerability exists in the data, program, and function file permissions func...

An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability.Required Keyswitch State: REMOTE or PROG Associated Fault Code: 0001 Fault Type: Non-User Description: A fault state can be triggered by setting the NVRAM/memory module user program mismatch bit (S2:9) when a memory module is NOT installed.

Published Apr 5, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13287: In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improp...

In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to local escalation of privilege if mPayload in writeToParcel were null, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-71714464.

Published Apr 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-13286: In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismat...

In writeToParcel and readFromParcel of OutputConfiguration.java, there is a permission bypass due to mismatched serialization. This could lead to a local escalation of privilege where the user can start an activity with system privileges, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-69683251.

Published Apr 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-14010: In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled...

In SpiderControl MicroBrowser Windows XP, Vista 7, 8 and 10, Versions 1.6.30.144 and prior, an uncontrolled search path element vulnerability has been identified which could be exploited by placing a specially crafted DLL file in the search path. If the malicious DLL is loaded prior to the valid DLL, an attacker could execute arbitrary code on the system.

Published Apr 26, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-1734: IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM...

IBM Jazz Team Server affecting the following IBM Rational Products: Collaborative Lifecycle Management (CLM), Rational DOORS Next Generation (RDNG), Rational Engineering Lifecycle Manager (RELM), Rational Team Concert (RTC), Rational Quality Manager (RQM), Rational Rhapsody Design Manager (Rhapsody DM), and Rational Software Architect (RSA DM) stores potentially sensitive information in a cache that could be read by authenticated users. IBM X-Force ID: 134915.

Published Apr 24, 2018 · Updated Sep 16, 2024