CVE-2017-1000410
- EPSS 1.92%
- Published 07.12.2017 19:29:00
- Last modified 20.04.2025 01:37:25
The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned...
CVE-2017-15121
- EPSS 0.07%
- Published 07.12.2017 02:29:13
- Last modified 20.04.2025 01:37:25
A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not end aligned to a page boundary.
CVE-2017-11281
- EPSS 45.37%
- Published 01.12.2017 08:29:00
- Last modified 20.04.2025 01:37:25
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
CVE-2017-11282
- EPSS 20.69%
- Published 01.12.2017 08:29:00
- Last modified 20.04.2025 01:37:25
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
CVE-2017-14746
- EPSS 28.33%
- Published 27.11.2017 22:29:00
- Last modified 20.04.2025 01:37:25
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
CVE-2017-15275
- EPSS 44.72%
- Published 27.11.2017 22:29:00
- Last modified 20.04.2025 01:37:25
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
CVE-2017-3157
- EPSS 1.06%
- Published 20.11.2017 20:29:00
- Last modified 20.04.2025 01:37:25
By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections...
CVE-2016-8610
- EPSS 69.1%
- Published 13.11.2017 22:29:00
- Last modified 20.04.2025 01:37:25
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL ser...
CVE-2015-7529
- EPSS 0.06%
- Published 06.11.2017 17:29:00
- Last modified 20.04.2025 01:37:25
sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by sosreport-$hostname-$date.tar in /tmp/sosreport-$host...
CVE-2017-16541
- EPSS 4.97%
- Published 04.11.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: T...