- EPSS 2.4%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-12617
- EPSS 94.37%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...
CVE-2015-7837
- EPSS 0.07%
- Veröffentlicht 19.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...
CVE-2017-12615
- EPSS 94.36%
- Veröffentlicht 19.09.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP...
CVE-2017-12896
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
CVE-2017-12899
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
CVE-2017-12902
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
CVE-2017-12987
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
- EPSS 4.19%
- Veröffentlicht 12.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...
CVE-2017-1000083
- EPSS 79.83%
- Veröffentlicht 05.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option su...