LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 5 of 30.

Unknown · CVSS Not scored

CVE-2017-16166: byucslabsix is an http server.

byucslabsix is an http server. byucslabsix is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16152: static-html-server is a static file server.

static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16177: chatbyvista is a file server.

chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16176: jansenstuffpleasework is a file server.

jansenstuffpleasework is a file server. jansenstuffpleasework is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16223: nodeaaaaa is a static file server.

nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16109: easyquick is a simple web server.

easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16192: getcityapi.yoehoehne is a web server.

getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-15854: The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can...

The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma_radio_chan_stats_event_handler() for the derived length len leading to a subsequent buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

Published Jun 12, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16211: lessindex is a static file server.

lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16200: uv-tj-demo is a static file server.

uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16191: cypserver is a static file server.

cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16170: liuyaserver is a static file server.

liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16021: uri-js is a module that tries to fully implement RFC 3986.

uri-js is a module that tries to fully implement RFC 3986. One of these features is validating whether or not a supplied URL is valid or not. To do this, uri-js uses a regular expression, This regular expression is vulnerable to redos. This causes the program to hang and the CPU to idle at 100% usage while uri-js is trying to validate if the supplied URL is valid or not. To check if you're vulnerable, look for a call to `require("uri-js").parse()` where a user is able to send their own input. This affects uri-js 2.1.1 and earlier.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-18070: In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if th...

In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of variable "event->num_ndp_end_rsp_per_ndi_list" is very large which can then lead to a heap overwrite of the heap object end_rsp in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.

Published Jun 12, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16101: serverwg is a simple http server.

serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16221: yzt is a simple file server.

yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16120: liyujing is a static file server.

liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16212: ltt is a static file server.

ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-9465: The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer...

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function in libyara/scan.c.

Published Jun 6, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16035: The hubl-server module is a wrapper for the HubL Development Server.

The hubl-server module is a wrapper for the HubL Development Server. During installation hubl-server downloads a set of dependencies from api.hubapi.com. It appears in the code that these files are downloaded over HTTPS however the api.hubapi.com endpoint redirects to a HTTP url. Because of this behavior an attacker with the ability to man-in-the-middle a developer or system performing a package installation could compromise the integrity of the installation.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-9829: '/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable...

'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnerability is already verified on VIVOTEK Network Camera IB8369/FD8164/FD816BA; most others have similar firmware that may be affected.

Published Jun 23, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16095: serverliujiayi1 is a simple http server.

serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16175: ewgaddis.lab6 is a file server.

ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024