LiveActive security incident?Get immediate response
CVE archive

September 2017

Browse CVE records published in September 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1095 matching CVEs · Page 14 of 22.

Unknown · CVSS Not scored

CVE-2017-14526: Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 a...

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list the contents of arbitrary directories, read arbitrary files, cause a denial of service, or, on Windows, obtain Documentum user hashes via a (1) crafted DTD, involving unspecified XML structures in a request to xda/com/documentum/ucf/server/transport/impl/GAIRConnector or crafted XML file in a MediaProfile file (2) import or (3) check in.

Published Sep 27, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14525: Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers t...

Multiple open redirect vulnerabilities in OpenText Documentum Webtop 6.8.0160.0073 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

Published Sep 27, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14511: An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617.

An issue was discovered in SAP E-Recruiting (aka ERECRUIT) 605 through 617. When an external applicant registers to the E-Recruiting application, he/she receives a link by email to confirm access to the provided email address. However, this measure can be bypassed and attackers can register and confirm email addresses that they do not have access to (candidate_hrobject is predictable and corr_act_guid is improperly validated). Furthermore, since an email address can be registered only once, an attacker could prevent other legitimate users from registering. This is SAP Security Note 2507798.

Published Sep 17, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14524: Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote atta...

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

Published Sep 27, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14510: An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sug...

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLeadCapture functionality is found vulnerable to unauthenticated cross-site scripting (XSS) attacks. This attack vector is mitigated by proper validating the redirect URL values being passed along.

Published Sep 17, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14507: Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote atta...

Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.

Published Sep 28, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14528: The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether...

The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-after-free after an invalid call to TIFFSetField, and application crash) via a crafted file.

Published Sep 18, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14483: flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file owners...

flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill `cat /pathname`" command.

Published Sep 15, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14508: An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sug...

An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several areas have been identified in the Documents and Emails module that could allow an authenticated user to perform SQL injection, as demonstrated by a backslash character at the end of a bean_id to modules/Emails/DetailView.php. An attacker could exploit these vulnerabilities by sending a crafted SQL request to the affected areas. An exploit could allow the attacker to modify the SQL database. Proper SQL escaping has been added to prevent such exploits.

Published Sep 17, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14500: Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbe...

Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.

Published Sep 17, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14420: The D-Link NPAPI extension, as used on D-Link DIR-850L REV.

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14424: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/passwd permissions.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14417: register_send.php on D-Link DIR-850L REV.

register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, which can result in unintended enrollment in mydlink Cloud Services.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14421: D-Link DIR-850L REV.

D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices have a hardcoded password of wrgac25_dlink.2013gui_dir850l for the Alphanetworks account upon device reset, which allows remote attackers to obtain root access via a TELNET session.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14425: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapasswd permissions.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14414: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/shareport.php.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14413: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/wpsacts.php.

Published Sep 13, 2017 · Updated Aug 5, 2024

Critical · CVSS 9.6

CVE-2017-14443: An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012.

An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Published Sep 17, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14427: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage_account_root permissions.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14415: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices have XSS in the action parameter to htdocs/web/sitesurvey.php.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14423: htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV.

htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does not prevent unauthenticated nonce-guessing attacks, which makes it easier for remote attackers to change the DNS configuration via a series of requests.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14419: The D-Link NPAPI extension, as used on D-Link DIR-850L REV.

The D-Link NPAPI extension, as used on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices, participates in mydlink Cloud Services by establishing a TCP relay service for HTTP, even though a TCP relay service for HTTPS is also established.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14426: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow (aka the /etc/shadow symlink target) permissions.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14430: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to cause a denial of service (daemon crash) via crafted LAN traffic.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-14422: D-Link DIR-850L REV.

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defeat the HTTPS cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Published Sep 13, 2017 · Updated Aug 5, 2024