LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 9 of 30.

Unknown · CVSS Not scored

CVE-2017-16098: charset 1.0.0 and below are vulnerable to regular expression denial of service.

charset 1.0.0 and below are vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds. Unless node was compiled using the -DHTTP_MAX_HEADER_SIZE= option the default header max length is 80kb, so the impact of the ReDoS is relatively low.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-6292: In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of boun...

In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due to integer overflow which could lead to local escalation of privilege in the TrustZone with no additional execution privileges needed. User interaction is not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69480285. Reference: N-CVE-2017-6292.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16190: dcdcdcdcdc is a static file server.

dcdcdcdcdc is a static file server. dcdcdcdcdc is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16008: i18next is a language translation framework.

i18next is a language translation framework. Because of how the interpolation is implemented, making replacements from the dictionary one at a time, untrusted user input can use the name of one of the dictionary keys to inject script into the browser. This affects i18next <=1.10.2.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16123: welcomyzt is a simple file server.

welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16024: The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9.

The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning values. Other users on the server have read access to the tmp directory, possibly allowing an attacker on the server to obtain confidential information from the buffer/tmp file, while it exists.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16188: reecerver is a web server.

reecerver is a web server. reecerver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16171: hcbserver is a static file server.

hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16026: Request is an http client.

Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16718: Beckhoff TwinCAT 3 supports communication over ADS.

Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.

Published Jun 27, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-6294: In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds...

In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to missing bounds check which could lead to escalation of privilege from the kernel to the TZ. User interaction is not needed for exploitation. This issue is rated as high. Version: N/A. Android: A-69316825. Reference: N-CVE-2017-6294.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16859: The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 b...

The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.

Published Jun 28, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16726: Beckhoff TwinCAT supports communication over ADS.

Beckhoff TwinCAT supports communication over ADS. ADS is a protocol for industrial automation in protected environments. ADS has not been designed to achieve security purposes and therefore does not include any encryption algorithms because of their negative effect on performance and throughput. An attacker can forge arbitrary ADS packets when legitimate ADS traffic is observable.

Published Jun 27, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16216: tencent-server is a simple web server.

tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16147: shit-server is a file server.

shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16089: serverlyr is a simple http server.

serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.

Published Jun 7, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16182: serverxxx is a static file server.

serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

Published Jun 7, 2018 · Updated Sep 16, 2024

Medium · CVSS 5.7

CVE-2017-5528: TIBCO JasperReports Server cross-site vulnerabilities

Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server (versions 6.1.1 and below, 6.2.0, 6.2.1, and 6.3.0), TIBCO JasperReports Server Community Edition (versions 6.3.0 and below), TIBCO JasperReports Server for ActiveMatrix BPM (versions 6.2.0 and below), TIBCO Jaspersoft for AWS with Multi-Tenancy (versions 6.2.0 and below), and TIBCO Jaspersoft Reporting and Analytics for AWS (versions 6.2.0 and below).

Published Jun 29, 2017 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16043: Shout is an IRC client.

Shout is an IRC client. Because the `/topic` command in messages is unescaped, attackers have the ability to inject HTML scripts that will run in the victim's browser. Affects shout >=0.44.0 <=0.49.3.

Published Jun 4, 2018 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2017-16151: Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered i...

Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.

Published Jun 7, 2018 · Updated Sep 16, 2024