LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 7 of 30.

Unknown · CVSS Not scored

CVE-2017-16209: enserver is a simple web server.

enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16140: lab6.brit95 is a file server.

lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16189: sly07 is an API for censoring text.

sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16186: 360class.jansenhm is a static file server.

360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16149: zwserver is a weather web server.

zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-9448: Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users t...

Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\modules\pages\revisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.

Published Jun 6, 2017 · Updated Sep 16, 2024

Medium · CVSS 5.9

CVE-2017-1476: IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a...

IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 128610.

Published Jun 6, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16015: Forms is a library for easily creating HTML forms.

Forms is a library for easily creating HTML forms. Versions before 1.3.0 did not have proper html escaping. This means that if the application did not sanitize html on behalf of forms, use of forms may be vulnerable to cross site scripting

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16199: susu-sum is a static file server.

susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16210: jn_jj_server is a static file server.

jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-9449: SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbi...

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.

Published Jun 6, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-6290: In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of boun...

In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due to an integer overflow which could lead to local escalation of privilege with no additional execution privileges needed. User interaction not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69559414. Reference: N-CVE-2017-6290.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16220: wind-mvc is an mvc framework.

wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16172: section2.madisonjbrooks12 is a simple web server.

section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16201: zjjserver is a static file server.

zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16194: picard is a micro framework.

picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16014: Http-proxy is a proxying library.

Http-proxy is a proxying library. Because of the way errors are handled in versions before 0.7.0, an attacker that forces an error can crash the server, causing a denial of service.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16031: Socket.io is a realtime application framework that provides communication via websockets.

Socket.io is a realtime application framework that provides communication via websockets. Because socket.io 0.9.6 and earlier depends on `Math.random()` to create socket IDs, the IDs are predictable. An attacker is able to guess the socket ID and gain access to socket.io servers, potentially obtaining sensitive information.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16174: whispercast is a file server.

whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16159: caolilinode is a simple file server.

caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16214: peiserver is a static file server.

peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16135: serverzyy is a static file server.

serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16224: st is a module for serving static files.

st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) to an entirely different domain. A request for: http://some.server.com//nodesecurity.org/%2e%2e would result in a 301 to //nodesecurity.org/%2e%2e which most browsers treat as a proper redirect as // is translated into the current schema being used. Mitigating factor: In order for this to work, st must be serving from the root of a server (/) rather than the typical sub directory (/static/) and the redirect URL will end with some form of URL encoded .. ("%2e%2e", "%2e.", ".%2e").

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16163: dylmomo is a simple file server.

dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16090: fsk-server is a simple http server.

fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16111: The content module is a module to parse HTTP Content-* headers.

The content module is a module to parse HTTP Content-* headers. It is used by the hapijs framework to provide this functionality. The module is vulnerable to regular expression denial of service when passed a specifically crafted Content-Type or Content-Disposition header.

Published Jun 7, 2018 · Updated Sep 16, 2024

High · CVSS 8.8

CVE-2017-2845: An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1...

An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary shell characters during the SMTP configuration tests resulting in command execution

Published Jun 29, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16146: mockserve is a file server.

mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024