CVE-2017-14494
- EPSS 15.41%
- Published 03.10.2017 01:29:02
- Last modified 20.04.2025 01:37:25
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
CVE-2017-14495
- EPSS 60.15%
- Published 03.10.2017 01:29:02
- Last modified 20.04.2025 01:37:25
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
CVE-2017-14496
- EPSS 15.74%
- Published 03.10.2017 01:29:02
- Last modified 20.04.2025 01:37:25
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CVE-2017-13704
- EPSS 81.76%
- Published 03.10.2017 01:29:01
- Last modified 20.04.2025 01:37:25
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platf...
CVE-2017-12615
- EPSS 94.36%
- Published 19.09.2017 13:29:00
- Last modified 20.04.2025 01:37:25
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP...
CVE-2017-12896
- EPSS 2.06%
- Published 14.09.2017 06:29:00
- Last modified 20.04.2025 01:37:25
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
CVE-2017-12899
- EPSS 2.06%
- Published 14.09.2017 06:29:00
- Last modified 20.04.2025 01:37:25
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
CVE-2017-12902
- EPSS 2.06%
- Published 14.09.2017 06:29:00
- Last modified 20.04.2025 01:37:25
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
CVE-2017-12987
- EPSS 2.06%
- Published 14.09.2017 06:29:00
- Last modified 20.04.2025 01:37:25
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
- EPSS 4.19%
- Published 12.09.2017 17:29:00
- Last modified 20.04.2025 01:37:25
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...