LiveActive security incident?Get immediate response
CVE archive

May 2017

Browse CVE records published in May 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 997 matching CVEs · Page 4 of 20.

Medium · CVSS 4.3

CVE-2017-5527: TIBCO Spotfire injection vulnerabilities

TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7.8.1 and Spotfire Analytics Platform for AWS Marketplace 7.8.0 and earlier contain multiple vulnerabilities which may allow authorized users to perform SQL injection attacks.

Published May 9, 2017 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-12125: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1...

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the CN= parm in the "/goform/net_WebCSRGen" uri to trigger this vulnerability.

Published May 14, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-15533: Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulner...

Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1 are vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. All affected SSLV versions act as weak oracles according the oracle classification used in the ROBOT research paper. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish multiple millions of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.

Published May 17, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16010: i18next is a language translation framework.

i18next is a language translation framework. When using the .init method, passing interpolation options without passing an escapeValue will default to undefined rather than the assumed true. This can result in a cross-site scripting vulnerability because user input is assumed to be escaped, but is not. This vulnerability affects i18next 2.0.0 and later.

Published May 29, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-12121: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1...

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the rsakey\_name= parm in the "/goform/WebRSAKEYGen" uri to trigger this vulnerability.

Published May 14, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-14432: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1...

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attacker can inject OS commands into the openvpnServer0_tmp= parameter in the "/goform/net\_Web\_get_value" uri to trigger this vulnerability.

Published May 14, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-3730: Bad (EC)DHE parameters cause a client crash

In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.

Published May 4, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-6293: In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widev...

In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

Published May 10, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-8419: LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows...

LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overflow or heap-based buffer overflow) or possibly have unspecified other impact via a crafted file, as demonstrated by mishandling of num_channels.

Published May 2, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-18268: Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) att...

Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can establish large numbers of crafted SSL connections to the target and obtain the session keys required to decrypt the pre-recorded SSL session.

Published May 17, 2018 · Updated Sep 16, 2024

High · CVSS 7.5

CVE-2017-14435: An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1...

An exploitable denial of service vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP URI can cause a null pointer dereference resulting in denial of service. An attacker can send a GET request to "/MOXA\_CFG.ini" without a cookie header to trigger this vulnerability.

Published May 14, 2018 · Updated Sep 16, 2024

Critical · CVSS 9.8

CVE-2017-14479: In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_...

In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of the mmm\_agentd process. An attacker that can initiate a TCP session with mmm\_agentd can trigger this vulnerability.

Published May 9, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-12120: An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1...

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An attacker can inject OS commands into the ip= parm in the "/goform/net_WebPingGetValue" URI to trigger this vulnerability.

Published May 14, 2018 · Updated Sep 16, 2024