CVE-2017-1000111
- EPSS 0.06%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
CVE-2017-1000115
- EPSS 2.14%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
- EPSS 6.64%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-12617
- EPSS 94.36%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 22.10.2025 00:16:04
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...
CVE-2015-7837
- EPSS 0.07%
- Veröffentlicht 19.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...
CVE-2017-12615
- EPSS 94.2%
- Veröffentlicht 19.09.2017 13:29:00
- Zuletzt bearbeitet 22.10.2025 00:16:04
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP...
CVE-2017-12896
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 04.12.2025 16:15:53
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
CVE-2017-12899
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 04.12.2025 16:15:57
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
CVE-2017-12902
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 04.12.2025 16:15:58
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
CVE-2017-12987
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().