CVE-2018-2579
- EPSS 0.11%
- Veröffentlicht 18.01.2018 02:29:18
- Zuletzt bearbeitet 21.11.2024 04:03:58
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Difficult to e...
CVE-2018-2588
- EPSS 0.48%
- Veröffentlicht 18.01.2018 02:29:18
- Zuletzt bearbeitet 21.11.2024 04:03:59
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: LDAP). Supported versions that are affected are Java SE: 6u171, 7u161, 8u152 and 9.0.1; Java SE Embedded: 8u151; JRockit: R28.3.16. Easily exploitable ...
CVE-2018-2562
- EPSS 0.36%
- Veröffentlicht 18.01.2018 02:29:17
- Zuletzt bearbeitet 21.11.2024 04:03:56
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows low privileged a...
CVE-2018-5345
- EPSS 0.75%
- Veröffentlicht 12.01.2018 00:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:37
A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.
CVE-2017-15129
- EPSS 0.07%
- Veröffentlicht 09.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:07
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in ne...
- EPSS 27.65%
- Veröffentlicht 03.01.2018 06:29:00
- Zuletzt bearbeitet 03.01.2025 12:15:25
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other im...
CVE-2017-17405
- EPSS 89.02%
- Veröffentlicht 15.12.2017 09:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command followi...
CVE-2017-1000407
- EPSS 0.46%
- Veröffentlicht 11.12.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
CVE-2017-1000410
- EPSS 1.92%
- Veröffentlicht 07.12.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned...
CVE-2017-15121
- EPSS 0.07%
- Veröffentlicht 07.12.2017 02:29:13
- Zuletzt bearbeitet 20.04.2025 01:37:25
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.