CVE-2017-9461
- EPSS 4.03%
- Published 06.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
- EPSS 48.7%
- Published 06.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
CVE-2017-9287
- EPSS 38.97%
- Published 29.05.2017 16:29:00
- Last modified 20.04.2025 01:37:25
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
CVE-2017-8291
- EPSS 92.68%
- Published 27.04.2017 01:59:02
- Last modified 20.04.2025 01:37:25
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" substring in a crafted .eps document that is an input to the gs program, as exploited in the wild in ...
CVE-2017-3600
- EPSS 0.89%
- Published 24.04.2017 19:59:06
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privi...
CVE-2017-3539
- EPSS 0.73%
- Published 24.04.2017 19:59:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthen...
CVE-2017-3544
- EPSS 0.38%
- Published 24.04.2017 19:59:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit...
CVE-2017-3533
- EPSS 0.65%
- Published 24.04.2017 19:59:03
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit...
CVE-2017-3453
- EPSS 0.27%
- Published 24.04.2017 19:59:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privi...
CVE-2017-3456
- EPSS 0.11%
- Published 24.04.2017 19:59:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged...