Search Results (7346 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2017-18342 2 Fedoraproject, Pyyaml 2 Fedora, Pyyaml 2024-11-21 9.8 Critical
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
CVE-2017-18188 1 Openr 1 Opentmpfiles 2024-11-21 N/A
OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run.
CVE-2017-18078 3 Debian, Opensuse, Systemd Project 3 Debian Linux, Leap, Systemd 2024-11-21 7.8 High
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.
CVE-2017-17691 1 Contronics 1 Homeputer Cl Studio Fur Homematic 2024-11-21 N/A
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
CVE-2017-17675 1 Bmc 1 Remedy Mid-tier 2024-11-21 5.3 Medium
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names and HTTP data.
CVE-2017-17406 1 Netgain-systems 1 Enterprise Manager 2024-11-21 N/A
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within an exposed RMI registry, which listens on TCP ports 1800 and 1850 by default. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute arbitrary code under the context of the current process. Was ZDI-CAN-4753.
CVE-2017-16770 1 Synology 1 Surveillance Station 2024-11-21 N/A
File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Surveillance Station before 8.1.2-5469 allows remote authenticated users to obtain other user's sensitive files via the filename parameter.
CVE-2017-16718 1 Beckhoff 1 Twincat 2024-11-21 N/A
Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol uses user configured routes, that can be edited remotely via ADS. This special command supports encrypted authentication with username/password. The encryption uses a fixed key, that could be extracted by an attacker. Precondition of the exploitation of this weakness is network access at the moment a route is added.
CVE-2017-16714 1 Iceqube 2 Thermal Management Center, Thermal Management Center Firmware 2024-11-21 N/A
In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.
CVE-2017-16207 1 Discordi.js Project 1 Discordi.js 2024-11-21 N/A
discordi.js is a malicious module based on the discord.js library that exfiltrates login tokens to pastebin.
CVE-2017-16205 1 Coffescript Project 1 Coffescript 2024-11-21 N/A
The coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16204 1 Jquey Project 1 Jquey 2024-11-21 N/A
The jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16203 1 Coffescript Project 1 Coffescript 2024-11-21 N/A
The coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16202 1 Cofeescript Project 1 Cofeescript 2024-11-21 N/A
The cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16128 1 Npm-script-demo Project 1 Npm-script-demo 2024-11-21 N/A
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
CVE-2017-16127 1 Pandora-doomsday Project 1 Pandora-doomsday 2024-11-21 N/A
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
CVE-2017-16081 1 Cross-env.js Project 1 Cross-env.js 2024-11-21 N/A
cross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16080 1 Nodesass Project 1 Nodesass 2024-11-21 N/A
nodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16079 1 Smb Project 1 Smb 2024-11-21 N/A
smb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078 1 Shadowsock Project 1 Shadowsock 2024-11-21 N/A
shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.