LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 6 of 30.

Unknown · CVSS Not scored

CVE-2017-16025: Nes is a websocket extension library for hapi.

Nes is a websocket extension library for hapi. Hapi is a webserver framework. Versions below and including 6.4.0 have a denial of service vulnerability via an invalid Cookie header. This is only present when websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to error out.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16103: serveryztyzt is a simple http server.

serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16196: quickserver is a simple static file server.

quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16030: Useragent is used to parse useragent headers.

Useragent is used to parse useragent headers. It uses several regular expressions to accomplish this. An attacker could edit their own headers, creating an arbitrarily long useragent string, causing the event loop and server to block. This affects Useragent 2.1.12 and earlier.

Published Jun 4, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16178: intsol-package is a file server.

intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-9442: BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a craft...

BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.

Published Jun 5, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16148: serve46 is a static file server.

serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16097: tiny-http is a simple http server.

tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 17, 2024

High · CVSS 8.8

CVE-2017-2850: In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a speci...

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary characters in the pureftpd.passwd file during a username change, which in turn allows for bypassing chroot restrictions in the FTP server. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 29, 2017 · Updated Sep 17, 2024

Unknown · CVSS Not scored

CVE-2017-16133: goserv is an http server.

goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16215: sgqserve is a simple file server.

sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16134: http_static_simple is an http server.

http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-2292: Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing t...

Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.

Published Jun 30, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16179: dasafio is a web server.

dasafio is a web server. dasafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. File access is restricted to only .html files.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16165: calmquist.static-server is a static file server.

calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16208: dmmcquay.lab6 is a REST server.

dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16102: serverhuwenhui is a simple http server.

serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-2847: In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a speci...

In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during manual network configuration resulting in command injection. An attacker can simply send an HTTP request to the device to trigger this vulnerability.

Published Jun 29, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16106: tmock is a static file server.

tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16180: serverabc is a static file server.

serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Low · CVSS 2.7

CVE-2017-9441: Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticate...

Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in core\admin\modules\developer\extensions\install\unpack.php and core\admin\modules\developer\packages\install\unpack.php. NOTE: the vendor states "You must implicitly trust any package or extension you install as they all have the ability to write PHP files.

Published Jun 5, 2017 · Updated Sep 16, 2024