CVE-2017-5071
- EPSS 0.78%
- Published 27.10.2017 05:29:00
- Last modified 20.04.2025 01:37:25
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-5073
- EPSS 0.91%
- Published 27.10.2017 05:29:00
- Last modified 20.04.2025 01:37:25
Use after free in print preview in Blink in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
CVE-2017-15906
- EPSS 2.76%
- Published 26.10.2017 03:29:00
- Last modified 20.04.2025 01:37:25
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
CVE-2017-12613
- EPSS 0.29%
- Published 24.10.2017 01:29:02
- Last modified 20.04.2025 01:37:25
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially r...
CVE-2017-11292
- EPSS 11.15%
- Published 22.10.2017 19:29:00
- Last modified 20.04.2025 01:37:25
Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could le...
CVE-2017-10378
- EPSS 0.36%
- Published 19.10.2017 17:29:05
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privile...
CVE-2017-10379
- EPSS 0.25%
- Published 19.10.2017 17:29:05
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Easily exploitable vulnerability allows low privilege...
CVE-2017-10384
- EPSS 0.47%
- Published 19.10.2017 17:29:05
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacke...
CVE-2017-10388
- EPSS 0.54%
- Published 19.10.2017 17:29:05
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Difficult to exploit vulnerability allows unau...
CVE-2017-10346
- EPSS 0.58%
- Published 19.10.2017 17:29:04
- Last modified 20.04.2025 01:37:25
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144. Easily exploitable vulnerability allows unauthen...