CVE-2017-3453
- EPSS 0.27%
- Published 24.04.2017 19:59:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privi...
CVE-2017-3456
- EPSS 0.11%
- Published 24.04.2017 19:59:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows high privileged...
CVE-2017-3464
- EPSS 0.25%
- Published 24.04.2017 19:59:01
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged ...
CVE-2017-3308
- EPSS 0.27%
- Published 24.04.2017 19:59:00
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged ...
CVE-2017-3309
- EPSS 0.27%
- Published 24.04.2017 19:59:00
- Last modified 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privi...
CVE-2016-5410
- EPSS 0.06%
- Published 19.04.2017 14:59:00
- Last modified 20.04.2025 01:37:25
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
CVE-2017-5645
- EPSS 94.01%
- Published 17.04.2017 21:59:00
- Last modified 20.04.2025 01:37:25
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
CVE-2016-4455
- EPSS 0.05%
- Published 14.04.2017 18:59:00
- Last modified 20.04.2025 01:37:25
The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directo...
CVE-2016-6489
- EPSS 1.68%
- Published 14.04.2017 18:59:00
- Last modified 20.04.2025 01:37:25
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.
CVE-2016-1908
- EPSS 2.61%
- Published 11.04.2017 18:59:00
- Last modified 20.04.2025 01:37:25
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding...