LiveActive security incident?Get immediate response
CVE archive

September 2017

Browse CVE records published in September 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1095 matching CVEs · Page 11 of 22.

Unknown · CVSS Not scored

CVE-2017-14867: Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14...

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

Published Sep 28, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14739: The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles...

The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory allocation, which allows remote attackers to cause a denial of service (NULL Pointer Dereference in DistortImage in MagickCore/distort.c, and application crash) via unspecified vectors.

Published Sep 26, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14796: The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of serv...

The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (integer underflow and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with copy_CTB_to_hv in hevc_filter.c in libavcodec in FFmpeg and sao_filter_CTB in hevc_filter.c in libavcodec in FFmpeg.

Published Sep 27, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14704: Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in...

Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.

Published Sep 26, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14694: Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single i...

Foxit Reader 8.3.2.25013 and earlier and Foxit PhantomPDF 8.3.2.25013 and earlier, when running in single instance mode, allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at tiptsf!CPenInputPanel::FinalRelease+0x000000000000002f.".

Published Sep 22, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14797: Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote att...

Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.

Published Sep 30, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14795: The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of serv...

The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a crafted BPG file, related to improper interaction with hls_pcm_sample in hevc.c in libavcodec in FFmpeg and put_pcm_var in hevcdsp_template.c in libavcodec in FFmpeg.

Published Sep 27, 2017 · Updated Aug 5, 2024