LiveActive security incident?Get immediate response
CVE archive

September 2017

Browse CVE records published in September 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1095 matching CVEs · Page 12 of 22.

Unknown · CVSS Not scored

CVE-2017-14687: Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact...

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016cb4f" on Windows. This occurs because of mishandling of XML tag name comparisons.

Published Sep 22, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14686: Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .x...

Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.

Published Sep 22, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14604: GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, a...

GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field.

Published Sep 20, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14685: Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact...

Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.

Published Sep 22, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14616: An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0.

An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management of the device becomes impossible.

Published Sep 20, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14596: In Joomla!

In Joomla! before 3.8.0, inadequate escaping in the LDAP authentication plugin can result in a disclosure of a username and password.

Published Sep 20, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14650: A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend...

A Remote Code Execution vulnerability has been found in the Horde_Image library when using the "Im" backend that utilizes ImageMagick's "convert" utility. It's not exploitable through any Horde application, because the code path to the vulnerability is not used by any Horde code. Custom applications using the Horde_Image library might be affected. This vulnerability affects all versions of Horde_Image from 2.0.0 to 2.5.1, and is fixed in 2.5.2. The problem is missing input validation of the index field in _raw() during construction of an ImageMagick command line.

Published Sep 21, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14615: An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0.

An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the user element, the code will be rendered in the context of any logged in user in the Web UI visiting "Traffic Monitor" sections "Events" and "All." As a side effect, no further events will be visible in the Traffic Monitor until the device is restarted.

Published Sep 20, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14595: In Joomla!

In Joomla! before 3.8.0, a logic bug in a SQL query could lead to the disclosure of article intro texts when these articles are in the archived state.

Published Sep 20, 2017 · Updated Aug 5, 2024