CVE-2017-14493
- EPSS 5.34%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
CVE-2017-14494
- EPSS 10.99%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
CVE-2017-14495
- EPSS 53.32%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
CVE-2017-14496
- EPSS 16.88%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CVE-2017-13704
- EPSS 79.32%
- Veröffentlicht 03.10.2017 01:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platf...
CVE-2015-7837
- EPSS 0.07%
- Veröffentlicht 19.09.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handling of secur...
CVE-2017-12615
- EPSS 94.2%
- Veröffentlicht 19.09.2017 13:29:00
- Zuletzt bearbeitet 21.04.2026 17:04:04
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP...
- EPSS 3.03%
- Veröffentlicht 12.09.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...
CVE-2017-1000083
- EPSS 76.67%
- Veröffentlicht 05.09.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option su...
CVE-2017-0899
- EPSS 7.36%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.