CVE-2017-14493
- EPSS 5.34%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
CVE-2015-3138
- EPSS 0.88%
- Veröffentlicht 28.09.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
print-wb.c in tcpdump before 4.7.4 allows remote attackers to cause a denial of service (segmentation fault and process crash).
CVE-2016-5759
- EPSS 0.03%
- Veröffentlicht 08.09.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
CVE-2017-6594
- EPSS 0.2%
- Veröffentlicht 28.08.2017 19:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The transit path validation code in Heimdal before 7.3 might allow attackers to bypass the capath policy protection mechanism by leveraging failure to add the previous hop realm to the transit path of issued tickets.
CVE-2014-3462
- EPSS 1.09%
- Veröffentlicht 07.08.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
CVE-2015-5203
- EPSS 0.6%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5221
- EPSS 0.23%
- Veröffentlicht 25.07.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5219
- EPSS 2.24%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVE-2015-5300
- EPSS 36.84%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option,...
CVE-2017-9814
- EPSS 0.36%
- Veröffentlicht 17.07.2017 13:18:30
- Zuletzt bearbeitet 13.05.2026 00:24:29
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call.