LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 28 of 30.

Unknown · CVSS Not scored

CVE-2017-3199: GraniteDS, version 3.1.1.GA, Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization

The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-3206: The Action Message Format (AMF3) deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages

The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or server side request forgery.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-3202: The implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes due to improper code control

The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instantiation of arbitrary classes via their public parameter-less constructor and subsequently call arbitrary Java Beans setter methods. The ability to exploit this vulnerability depends on the availability of classes in the class path that make use of deserialization. A remote attacker with the ability to spoof or control information may be able to send serialized Java objects with pre-set properties that result in arbitrary code execution when deserialized.

Published Jun 11, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-3203: Pivotal/Spring Spring-flex's Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization

The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.

Published Jun 11, 2018 · Updated Aug 5, 2024

High · CVSS 8.1

CVE-2017-2830: An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 I...

An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2842: In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a spe...

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 27, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2843: In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a spe...

In the web management interface in Foscam C1 Indoor HD Camera running application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 27, 2017 · Updated Aug 5, 2024

High · CVSS 7.7

CVE-2017-2829: An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam...

An exploitable directory traversal vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause the application to read a file from disk but a failure to adequately filter characters results in allowing an attacker to specify a file outside of a directory. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2841: An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1...

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msmtprc" configuration file resulting in command execution. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 27, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2828: An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1...

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

Critical · CVSS 9.1

CVE-2017-2831: An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 I...

An exploitable buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can cause a buffer overflow resulting in overwriting arbitrary data. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2827: An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1...

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during account creation resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

High · CVSS 8.8

CVE-2017-2813: An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44.

An exploitable integer overflow vulnerability exists in the JPEG 2000 parser functionality of IrfanView 4.44. A specially crafted jpeg2000 image can cause an integer overflow leading to wrong memory allocation resulting in arbitrary code execution. Vulnerability can be triggered by viewing the image in via the application or by using thumbnailing feature of IrfanView.

Published Jun 21, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-2773: An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior...

An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an "Unauthenticated JWT signing algorithm in multiple components" issue.

Published Jun 13, 2017 · Updated Aug 5, 2024

Medium · CVSS 6.5

CVE-2017-2782: An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure Matr...

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

Published Jun 22, 2017 · Updated Aug 5, 2024

Critical · CVSS 9.8

CVE-2017-2805: An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the...

An exploitable stack-based buffer overflow vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera. A specially crafted http request can cause a stack-based buffer overflow resulting in overwriting arbitrary data on the stack frame. An attacker can simply send an http request to the device to trigger this vulnerability.

Published Jun 21, 2017 · Updated Aug 5, 2024

High · CVSS 8.1

CVE-2017-2781: An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of I...

An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection.

Published Jun 22, 2017 · Updated Aug 5, 2024

High · CVSS 8.1

CVE-2017-2780: An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of I...

An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection.

Published Jun 22, 2017 · Updated Aug 5, 2024

Low · CVSS 3.7

CVE-2017-2669: Dovecot before version 2.2.29 is vulnerable to a denial of service.

Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_expand() to perform %variable expansion. Sending specially crafted %variable fields could result in excessive memory usage causing the process to crash (and restart), or excessive CPU usage causing all authentications to hang.

Published Jun 21, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-2209: Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the fir...

Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017 April 4) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

Published Jun 9, 2017 · Updated Aug 5, 2024