Vulnerabilities (CVE)

Filtered by CWE-200
Total 11067 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18321 1 Qualcomm 8 Mdm9650, Mdm9650 Firmware, Mdm9655 and 5 more 2026-06-17 2.1 LOW 5.5 MEDIUM
Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.
CVE-2017-18307 1 Qualcomm 14 Sd 450, Sd 450 Firmware, Sd 625 and 11 more 2026-06-17 N/A 8.4 HIGH
Information disclosure possible while audio playback.
CVE-2017-18306 1 Qualcomm 14 Sd 450, Sd 450 Firmware, Sd 625 and 11 more 2026-06-17 N/A 8.4 HIGH
Information disclosure due to uninitialized variable.
CVE-2017-18300 1 Qualcomm 16 Mdm9206, Mdm9206 Firmware, Mdm9607 and 13 more 2026-06-17 4.9 MEDIUM 5.5 MEDIUM
Secure display content could be accessed by third party trusted application after creating a fault in other trusted applications in Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, SD 210/SD 212/SD 205, SD 835, SDA660.
CVE-2017-18192 1 Photo\,video Locker-calculator Project 1 Photo\,video Locker-calculator 2026-06-17 5.0 MEDIUM 7.5 HIGH
smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN.
CVE-2017-18112 1 Atlassian 1 Fisheye 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Affected versions of Atlassian Fisheye allow remote attackers to view the HTTP password of a repository via an Information Disclosure vulnerability in the logging feature. The affected versions are before version 4.8.3.
CVE-2017-18104 1 Atlassian 2 Jira, Jira Server 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
The Webhooks component of Atlassian Jira before version 7.6.7 and from version 7.7.0 before version 7.11.0 allows remote attackers who are able to observe or otherwise intercept webhook events to learn information about changes in issues that should not be sent because they are not contained within the results of a specified JQL query.
CVE-2017-18072 1 Qualcomm 76 Mdm9206, Mdm9206 Firmware, Mdm9607 and 73 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, Snapdragon_High_Med_2016, the probe requests originated from user's phone contains the information elements which specifies the supported wifi features. This shall impact the user's privacy if someone sniffs the probe requests originated by this DUT. Hence, control the presence of which information elements is supported.
CVE-2017-17926 1 Ordermanagementscript 1 Professional Service Script 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
CVE-2017-17898 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 5.0 MEDIUM 7.5 HIGH
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.
CVE-2017-17864 2 Debian, Linux 2 Debian Linux, Linux Kernel 2026-06-17 2.1 LOW 3.3 LOW
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer leak."
CVE-2017-17793 1 Blogotext Project 1 Blogotext 2026-06-17 5.0 MEDIUM 7.5 HIGH
Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection mechanism, and read backup archives on Windows servers, by providing the archiv~1.zip name (aka an 8.3 filename).
CVE-2017-17776 1 Paid To Read Script Project 1 Paid To Read Script 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
CVE-2017-17769 1 Google 1 Android 2026-06-17 2.1 LOW 5.5 MEDIUM
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
CVE-2017-17735 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in cookies.
CVE-2017-17734 1 Cmsmadesimple 1 Cms Made Simple 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.
CVE-2017-17696 1 Techno - Portfolio Management Panel Project 1 Techno - Portfolio Management Panel 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php.
CVE-2017-17692 1 Samsung 1 Internet Browser 2026-06-17 5.0 MEDIUM 7.5 HIGH
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
CVE-2017-17556 1 Hp 1 Synaptics Touchpad Driver 2026-06-17 3.6 LOW 5.1 MEDIUM
A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.
CVE-2017-17549 1 Citrix 2 Application Delivery Controller Firmware, Netscaler Gateway Firmware 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build 71.22, 11.1 before build 56.19, and 12.0 before build 53.22 allow remote attackers to obtain sensitive information from the backend client TLS handshake by leveraging use of TLS with Client Certificates and a Diffie-Hellman Ephemeral (DHE) key exchange.