LiveActive security incident?Get immediate response
CVE archive

September 2017

Browse CVE records published in September 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1095 matching CVEs · Page 19 of 22.

Unknown · CVSS Not scored

CVE-2017-12794: In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the...

In Django 1.10.x before 1.10.8 and 1.11.x before 1.11.5, HTML autoescaping was disabled in a portion of the template for the technical 500 debug page. Given the right circumstances, this allowed a cross-site scripting attack. This vulnerability shouldn't affect most production sites since you shouldn't run with "DEBUG = True" (which makes this page accessible) in your production settings.

Published Sep 7, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-12733: A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSent...

A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. An attacker may create an application user account to gain administrative privileges.

Published Sep 9, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-12731: A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel...

A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via the input from the client.

Published Sep 9, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-12612: In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its...

In Apache Spark 1.6.0 until 2.1.1, the launcher API performs unsafe deserialization of data received by its socket. This makes applications launched programmatically using the launcher API potentially vulnerable to arbitrary code execution by an attacker with access to any user account on the local machine. It does not affect apps run by spark-submit or spark-shell. The attacker would be able to execute code as the user that ran the Spark application. Users are encouraged to update to version 2.2.0 or later.

Published Sep 13, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-12416: Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Pa...

Cross-site scripting (XSS) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.x before 7.0.17, 7.1.x before 7.1.12, and 8.0.x before 8.0.3 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper request parameter validation.

Published Sep 7, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2017-12230: A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated,...

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileges on an affected device. The vulnerability is due to incorrect default permission settings for new users who are created by using the web UI of the affected software. An attacker could exploit this vulnerability by using the web UI of the affected software to create a new user and then logging into the web UI as the newly created user. A successful exploit could allow the attacker to elevate their privileges on the affected device. This vulnerability affects Cisco devices that are running a vulnerable release Cisco IOS XE Software, if the HTTP Server feature is enabled for the device. The newly redesigned, web-based administration UI was introduced in the Denali 16.2 Release of Cisco IOS XE Software. This vulnerability does not affect the web-based administration UI in earlier releases of Cisco IOS XE Software. Cisco Bug IDs: CSCuy83062.

Published Sep 28, 2017 · Updated Aug 5, 2024