CVE-2017-3000 to CVE-2017-3999
56 CVEs with public proof-of-concept exploits.
- CVE-2017-30001 PoCAdobe Flash Player versions 24.0.0.221 and earlier have a vulnerability in the random number generator used for constant blinding.…
- CVE-2017-30062 PoCsAdobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation…
- CVE-2017-30611 PoCAdobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful…
- CVE-2017-30641 PoCAdobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline.…
- CVE-2017-30666 PoCsKEVAdobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java…
- CVE-2017-30681 PoCAdobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding…
- CVE-2017-30761 PoCAdobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC module.…
- CVE-2017-30771 PoCAdobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful…
- CVE-2017-30782 PoCsAdobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF)…
- CVE-2017-31061 PoCAdobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF files. Successful…
- CVE-2017-31312 PoCsA Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized…
- CVE-2017-31322 PoCsA Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or…
- CVE-2017-31332 PoCsA Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or…
- CVE-2017-31411 PoCWindows service and uninstall paths are not quoted when BIND is installed
- CVE-2017-31431 PoCAn error in TSIG authentication can permit unauthorized dynamic updates
- CVE-2017-31641 PoCServer Side Request Forgery in Apache Solr, versions 1.3 until 7.6 (inclusive). Since the "shards" parameter does not have a corresponding…
- CVE-2017-31651 PoCIn Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site scripting where one authenticated user can cause scripts to…
- CVE-2017-31951 PoCCommvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer…
- CVE-2017-31961 PoCPCAUSA Rawether framework does not properly validate BPF data, allowing a crafted malicious BPF program to perform operations on memory…
- CVE-2017-31972 PoCsGIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
- CVE-2017-31981 PoCGIGABYTE BRIX UEFI firmware is not cryptographically signed
- CVE-2017-31991 PoCGraniteDS, version 3.1.1.GA, Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization
- CVE-2017-32001 PoCThe implementation of Action Message Format (AMF3) deserializers in GraniteDS, version 3.1.1.GA, may allow instantiation of arbitrary…
- CVE-2017-32011 PoCFlamingo amf-serializer by Exadel, version 2.2.0, Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization
- CVE-2017-32021 PoCThe implementation of Action Message Format (AMF3) deserializers in Flamingo amf-serializer by Exadel, version 2.2.0, may allow…
- CVE-2017-32031 PoCPivotal/Spring Spring-flex's Action Message Format (AMF3) Java implementation is vulnerable to insecure deserialization
- CVE-2017-32061 PoCThe Action Message Format (AMF3) deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references…
- CVE-2017-32071 PoCWebORB for Java by Midnight Coders, version 5.1.1.0, Action Message Format (AMF3) Java implementation is vulnerable to insecure…
- CVE-2017-32081 PoCThe Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity…
- CVE-2017-32413 PoCsVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are…
- CVE-2017-32485 PoCsVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Supported versions that…
- CVE-2017-33161 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are…
- CVE-2017-35066 PoCsKEVVulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that…
- CVE-2017-35282 PoCsVulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values,…
- CVE-2017-35461 PoCVulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework).…
- CVE-2017-35482 PoCsVulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker).…
- CVE-2017-35492 PoCsVulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions…
- CVE-2017-35581 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected…
- CVE-2017-35611 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected…
- CVE-2017-35631 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected…
- CVE-2017-35751 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected…
- CVE-2017-35761 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected…
- CVE-2017-35871 PoCVulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported versions that are…
- CVE-2017-35993 PoCsVulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected…
- CVE-2017-36222 PoCsVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The…
- CVE-2017-36231 PoCVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are…
- CVE-2017-36293 PoCsVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected…
- CVE-2017-36303 PoCsVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected…
- CVE-2017-36313 PoCsVulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected…
- CVE-2017-37302 PoCsBad (EC)DHE parameters cause a client crash
- CVE-2017-38071 PoCA vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software, Major Releases…
- CVE-2017-38131 PoCA vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an…
- CVE-2017-38231 PoCAn issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on…
- CVE-2017-388114 PoCsKEVA vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an…
- CVE-2017-38971 PoCA Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and…
- CVE-2017-38981 PoCA man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to…