CVE-2016-8743
- EPSS 8.41%
- Published 27.07.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in...
CVE-2017-7980
- EPSS 0.17%
- Published 25.07.2017 14:29:00
- Last modified 20.04.2025 01:37:25
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display a...
CVE-2015-7703
- EPSS 4.95%
- Published 24.07.2017 14:29:00
- Last modified 20.04.2025 01:37:25
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and w...
CVE-2017-10978
- EPSS 3.31%
- Published 17.07.2017 17:29:00
- Last modified 20.04.2025 01:37:25
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
CVE-2017-9788
- EPSS 47.95%
- Published 13.07.2017 16:29:00
- Last modified 20.04.2025 01:37:25
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-9775
- EPSS 0.78%
- Published 22.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
CVE-2017-9776
- EPSS 1.25%
- Published 22.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
CVE-2017-3167
- EPSS 9.44%
- Published 20.06.2017 01:29:00
- Last modified 20.04.2025 01:37:25
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
CVE-2017-7668
- EPSS 65.46%
- Published 20.06.2017 01:29:00
- Last modified 20.04.2025 01:37:25
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...
CVE-2017-1000366
- EPSS 7.81%
- Published 19.06.2017 16:29:00
- Last modified 20.04.2025 01:37:25
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...