Vulnerabilities (CVE)

Filtered by CWE-20
Total 13258 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-9142 2 Debian, Imagemagick 2 Debian Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
CVE-2017-9141 2 Debian, Imagemagick 2 Debian Linux, Imagemagick 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
CVE-2017-9131 1 Mimosa 2 Backhaul Radios, Client Radios 2026-06-17 5.0 MEDIUM 7.5 HIGH
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its clients, an attacker can gather enough information to craft a command that reboots the client remotely when sent to the client's Mosquitto broker, aka "unauthenticated remote command execution." This command can be re-sent endlessly to act as a DoS attack on the client.
CVE-2017-9091 1 Allen Disk Project 1 Allen Disk 2026-06-17 5.0 MEDIUM 7.5 HIGH
/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['captcha'].
CVE-2017-9090 1 Allen Disk Project 1 Allen Disk 2026-06-17 5.0 MEDIUM 7.5 HIGH
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].
CVE-2017-9065 2 Debian, Wordpress 2 Debian Linux, Wordpress 2026-06-17 5.0 MEDIUM 7.5 HIGH
In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.
CVE-2017-9046 1 Pmail 1 Pegasus 2026-06-17 4.4 MEDIUM 7.3 HIGH
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
CVE-2017-9043 1 Gnu 1 Binutils 2026-06-17 6.8 MEDIUM 7.8 HIGH
readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.
CVE-2017-9034 1 Trendmicro 1 Serverprotect 2026-06-17 10.0 HIGH 9.8 CRITICAL
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.
CVE-2017-9022 3 Canonical, Debian, Strongswan 3 Ubuntu Linux, Debian Linux, Strongswan 2026-06-17 5.0 MEDIUM 7.5 HIGH
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
CVE-2017-8994 1 Hp 1 Operations Orchestration 2026-06-17 7.5 HIGH 9.8 CRITICAL
A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
CVE-2017-8983 1 Hp 1 Intelligent Management Center 2026-06-17 9.0 HIGH 8.8 HIGH
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
CVE-2017-8981 1 Hp 1 Intelligent Management Center 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.
CVE-2017-8977 1 Hp 1 Moonshot Provisioning Manager Appliance 2026-06-17 8.5 HIGH 9.1 CRITICAL
A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8976 1 Hp 1 Moonshot Provisioning Manager Appliance 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8975 1 Hp 1 Moonshot Provisioning Manager Appliance 2026-06-17 10.0 HIGH 9.8 CRITICAL
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
CVE-2017-8973 1 Hp 1 Matrix Operating Environment 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-8972 1 Hp 1 Matrix Operating Environment 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-8971 1 Hp 1 Matrix Operating Environment 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
A clickjacking vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
CVE-2017-8969 1 Hp 1 Insight Control 2026-06-17 3.5 LOW 5.7 MEDIUM
An improper input validation vulnerability in HPE Insight Control version 7.6 LR1 was found.