CVE-2017-7980
- EPSS 0.14%
- Veröffentlicht 25.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display a...
CVE-2015-7703
- EPSS 9.42%
- Veröffentlicht 24.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and w...
CVE-2017-10978
- EPSS 2.58%
- Veröffentlicht 17.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
CVE-2017-9788
- EPSS 49.5%
- Veröffentlicht 13.07.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-9775
- EPSS 0.74%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
CVE-2017-9776
- EPSS 1.25%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
CVE-2017-3167
- EPSS 8.72%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
CVE-2017-7668
- EPSS 62.78%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...
CVE-2017-1000366
- EPSS 8.87%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...
CVE-2017-9461
- EPSS 3.38%
- Veröffentlicht 06.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.