LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 4 of 30.

High · CVSS 8.8

CVE-2017-20123: Viscosity DLL untrusted search path

A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 30, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20124: Online Hotel Booking System Pro Plugin roomtype-details.php sql injection

A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 30, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20125: Online Hotel Booking System Pro roomtype-details.php sql injection

A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 30, 2022 · Updated Apr 15, 2025

High · CVSS 7.5

CVE-2017-20022: Solare Solar-Log information disclosure

A vulnerability has been found in Solare Solar-Log 2.8.4-56/3.5.2-85 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to information disclosure. The attack can be initiated remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 9, 2022 · Updated Apr 15, 2025

Unknown · CVSS Not scored

CVE-2017-6779: Multiple Cisco products are affected by a vulnerability in local file management for certain system log fil...

Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file is allowed to consume the majority of available disk space on the appliance. An attacker could exploit this vulnerability by sending crafted remote connection requests to the appliance. Successful exploitation could allow the attacker to increase the size of a system log file so that it consumes most of the disk space. The lack of available disk space could lead to a DoS condition in which the application functions could operate abnormally, making the appliance unstable. This vulnerability affects the following Cisco Voice Operating System (VOS)-based products: Emergency Responder, Finesse, Hosted Collaboration Mediation Fulfillment, MediaSense, Prime License Manager, SocialMiner, Unified Communications Manager (UCM), Unified Communications Manager IM and Presence Service (IM&P - earlier releases were known as Cisco Unified Presence), Unified Communication Manager Session Management Edition (SME), Unified Contact Center Express (UCCx), Unified Intelligence Center (UIC), Unity Connection, Virtualized Voice Browser. This vulnerability also affects Prime Collaboration Assurance and Prime Collaboration Provisioning. Cisco Bug IDs: CSCvd10872, CSCvf64322, CSCvf64332, CSCvi29538, CSCvi29543, CSCvi29544, CSCvi29546, CSCvi29556, CSCvi29571, CSCvi31738, CSCvi31741, CSCvi31762, CSCvi31807, CSCvi31818, CSCvi31823.

Published Jun 7, 2018 · Updated Nov 29, 2024

Unknown · CVSS Not scored

CVE-2017-9505: Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page...

Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain the content of comments, for comments added to a page after they started watching it even if they do not have permission to view the page itself.

Published Jun 15, 2017 · Updated Oct 16, 2024

High · CVSS 8.8

CVE-2017-8907: Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deploy...

Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project had the edit permission and therefore the rights to do so. An attacker who can login to Bamboo as a user without the edit permission for deployment projects is able to use this vulnerability, provided there is an existing plan with a green build, to create a deployment project and execute arbitrary code on an available Bamboo Agent. By default a local agent is enabled; this means that code execution can occur on the system hosting Bamboo as the user running Bamboo.

Published Jun 14, 2017 · Updated Oct 16, 2024

Unknown · CVSS Not scored

CVE-2017-3631: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data as well as unauthorized read access to a subset of Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

Published Jun 22, 2017 · Updated Oct 7, 2024

Unknown · CVSS Not scored

CVE-2017-3630: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Solaris accessible data as well as unauthorized read access to a subset of Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. CVSS 3.0 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

Published Jun 22, 2017 · Updated Oct 7, 2024

Unknown · CVSS Not scored

CVE-2017-3629: Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Published Jun 22, 2017 · Updated Oct 4, 2024

High · CVSS 8.8

CVE-2017-9443: BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted...

BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and core\admin\modules\developer\packages\install\process.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.

Published Jun 5, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16185: uekw1511server is a static file server.

uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16013: hapi is a web and services application framework.

hapi is a web and services application framework. When hapi >= 15.0.0 <= 16.1.0 encounters a malformed `accept-encoding` header an uncaught exception is thrown. This may cause hapi to crash or to hang the client connection until the timeout period is reached.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16150: wanggoujing123 is a simple webserver.

wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16082: A remote code execution vulnerability was found within the pg module when the remote database or query spec...

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16181: wintiwebdev is a static file server.

wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16222: elding is a simple web server.

elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing "../" in the url. The files accessible, however, are limited to files with a file extension. Sending a GET request to /../../../etc/passwd, for example, will return a 404 on etc/passwd/index.js.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16130: exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide.

exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to those with a file extension. Files with no extension such as /etc/passwd throw an error.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16162: 22lixian is a simple file server.

22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-9444: BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modi...

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.

Published Jun 5, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-0642: A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specia...

A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34819017.

Published Jun 14, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16096: serveryaozeyan is a simple HTTP server.

serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16093: cyber-js is a simple http server.

cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16136: method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELET...

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16139: jikes is a file server.

jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Accessible files are restricted to files with .htm and .js extensions.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16213: mfrserver is a simple file server.

mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16006: Remarkable is a markdown parser.

Remarkable is a markdown parser. In versions 1.6.2 and lower, remarkable allows the use of `data:` URIs in links and can therefore execute javascript.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16197: qinserve is a static file server.

qinserve is a static file server. qinserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Medium · CVSS 4.1

CVE-2017-5529: TIBCO JasperReports Library Information Disclosure

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO JasperReports Professional (versions 6.2.1 and below, and 6.3.0), TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.3.0 and below), TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.3.0 and below), and TIBCO Jaspersoft Studio for ActiveMatrix BPM (versions 6.2.0 and below).

Published Jun 29, 2017 · Updated Sep 17, 2024