LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 26 of 30.

Unknown · CVSS Not scored

CVE-2017-5378: Hashed codes of JavaScript objects are shared between pages.

Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5374: Memory safety bugs were reported in Firefox 50.1.

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5399: Memory safety bugs were reported in Firefox 51.

Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5243: The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not speci...

The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks.

Published Jun 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5373: Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6.

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5407: Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page c...

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5393: The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publ...

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5389: WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriat...

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5244: Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests.

Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running Metasploit tasks by getting an authenticated user to execute JavaScript. As of Metasploit 4.14.0 (Update 2017061301), the routes for stopping tasks only allow POST requests, which validate the presence of a secret token to prevent CSRF attacks.

Published Jun 15, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5394: A location bar spoofing attack where the location bar of loaded page will be shown over the content of anot...

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5384: Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full U...

Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is specified by the user or machine owner and presumed to be non-malicious, but if a user has enabled Web Proxy Auto Detect (WPAD) this file can be served remotely. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5392: Weak proxy objects have weak references on multiple threads when they should only have them on one, resulti...

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-5395: Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location...

Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4971: An issue was discovered in Pivotal Spring Web Flow through 2.4.4.

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.

Published Jun 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4973: An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x vers...

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. A vulnerability has been identified with the groups endpoint in UAA allowing users to elevate their privileges.

Published Jun 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4984: In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an una...

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an attacker to run arbitrary code with root-level privileges on the targeted VNX Control Station system, aka remote code execution.

Published Jun 19, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4966: An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6...

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior to 1.7.15. RabbitMQ management UI stores signed-in user credentials in a browser's local storage without expiration, making it possible to retrieve them using a chained attack.

Published Jun 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4989: In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenti...

In EMC Avamar Server Software 7.3.1-125, 7.3.0-233, 7.3.0-226, 7.2.1-32, 7.2.1-31, 7.2.0-401, an unauthenticated remote attacker may potentially bypass the authentication process to gain access to the system maintenance page. This may be exploited by an attacker to view sensitive information, perform software updates, or run maintenance workflows.

Published Jun 21, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4987: In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a loca...

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on the targeted VNX Control Station system, aka an uncontrolled search path vulnerability.

Published Jun 19, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-4994: An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x vers...

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior to v24.11, 30.x versions prior to 30.4, and other versions prior to v40. There was an issue with forwarded http headers in UAA that could result in account corruption.

Published Jun 13, 2017 · Updated Aug 5, 2024