Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 35961 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000168 1 Sodiumoxide Project 1 Sodiumoxide 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys
CVE-2017-1000152 1 Mahara 1 Mahara 2026-06-17 7.5 HIGH 9.8 CRITICAL
Mahara 15.04 before 15.04.7 and 15.10 before 15.10.3 running PHP 5.3 are vulnerable to one user being logged in as another user on a separate computer as the same session ID is served. This situation can occur when a user takes an action that forces another user to be logged out of Mahara, such as an admin changing another user's account settings.
CVE-2017-1000145 1 Mahara 1 Mahara 2026-06-17 4.0 MEDIUM 4.9 MEDIUM
Mahara 1.9 before 1.9.7 and 1.10 before 1.10.5 and 15.04 before 15.04.2 are vulnerable to anonymous comments being able to be placed on artefact detail pages even when the site administrator had disallowed anonymous comments.
CVE-2017-1000142 1 Mahara 1 Mahara 2026-06-17 5.5 MEDIUM 6.5 MEDIUM
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are vulnerable to users being able to delete their submitted page through URL manipulation.
CVE-2017-1000107 1 Jenkins 1 Script Security 2026-06-17 6.5 MEDIUM 8.8 HIGH
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and methods, bypassing sandbox protection.
CVE-2017-1000083 3 Debian, Gnome, Redhat 8 Debian Linux, Evince, Enterprise Linux Desktop and 5 more 2026-06-17 6.8 MEDIUM 7.8 HIGH
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the beginning of the filename.
CVE-2017-1000080 1 Onosproject 1 Onos 2026-06-17 5.0 MEDIUM 7.5 HIGH
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
CVE-2017-1000079 1 Onosproject 1 Onos 2026-06-17 5.0 MEDIUM 7.5 HIGH
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
CVE-2017-1000066 1 Keepass 1 Keepass 2026-06-17 5.0 MEDIUM 7.5 HIGH
The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information.
CVE-2017-1000046 1 Mautic 1 Mautic 2026-06-17 5.0 MEDIUM 7.5 HIGH
Mautic 2.6.1 and earlier fails to set flags on session cookies
CVE-2017-1000037 1 Rvm Project 1 Rvm 2026-06-17 7.5 HIGH 9.8 CRITICAL
RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when automatically loading environment variables from files in $PWD RVM automatically executes hooks located in $PWD resulting in code execution RVM automatically installs gems as specified by files in $PWD resulting in code execution RVM automatically does "bundle install" on a Gemfile specified by .versions.conf in $PWD resulting in code execution
CVE-2017-0909 1 Private Address Check Project 1 Private Address Check 2026-06-17 7.5 HIGH 9.8 CRITICAL
The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.
CVE-2017-0880 1 Google 1 Android 2026-06-17 7.1 HIGH 6.5 MEDIUM
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID A-65646012.
CVE-2017-0871 1 Google 1 Android 2026-06-17 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability in the Android framework (framework base). Product: Android. Versions: 8.0. Android ID A-65281159.
CVE-2017-0870 1 Google 1 Android 2026-06-17 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability in the Android framework (libminikin). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-62134807.
CVE-2017-0865 1 Google 1 Android 2026-06-17 4.6 MEDIUM 7.8 HIGH
An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-65025090. References: M-ALPS02973195.
CVE-2017-0864 1 Google 1 Android 2026-06-17 4.6 MEDIUM 7.8 HIGH
An elevation of privilege vulnerability in the MediaTek ioctl (flashlight). Product: Android. Versions: Android kernel. Android ID: A-37277147. References: M-ALPS03394571.
CVE-2017-0863 1 Google 1 Android 2026-06-17 4.6 MEDIUM 7.8 HIGH
An elevation of privilege vulnerability in the Upstream kernel video driver. Product: Android. Versions: Android kernel. Android ID: A-37950620.
CVE-2017-0862 1 Google 1 Android 2026-06-17 7.2 HIGH 7.8 HIGH
An elevation of privilege vulnerability in the Upstream kernel kernel. Product: Android. Versions: Android kernel. Android ID: A-36006779.
CVE-2017-0860 1 Google 1 Android 2026-06-17 4.6 MEDIUM 5.3 MEDIUM
An elevation of privilege vulnerability in the Android system (inputdispatcher). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-31097064.