CVE-2017-5525
- EPSS 0.14%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CVE-2017-5526
- EPSS 0.09%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CVE-2017-5579
- EPSS 0.13%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug ope...
CVE-2017-5938
- EPSS 0.63%
- Veröffentlicht 15.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
CVE-2017-6060
- EPSS 3.29%
- Veröffentlicht 15.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.
CVE-2017-6814
- EPSS 2.42%
- Veröffentlicht 12.03.2017 01:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In WordPress before 4.7.3, there is authenticated Cross-Site Scripting (XSS) via Media File Metadata. This is demonstrated by both (1) mishandling of the playlist shortcode in the wp_playlist_shortcode function in wp-includes/media.php and (2) mishan...
CVE-2017-6815
- EPSS 6.39%
- Veröffentlicht 12.03.2017 01:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.
CVE-2017-6816
- EPSS 2.19%
- Veröffentlicht 12.03.2017 01:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In WordPress before 4.7.3 (wp-admin/plugins.php), unintended files can be deleted by administrators using the plugin deletion functionality.
CVE-2017-6817
- EPSS 6.48%
- Veröffentlicht 12.03.2017 01:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In WordPress before 4.7.3 (wp-includes/embed.php), there is authenticated Cross-Site Scripting (XSS) in YouTube URL Embeds.
CVE-2016-8714
- EPSS 0.69%
- Veröffentlicht 10.03.2017 10:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A specially crafted R script can cause a buffer overflow resulting in a memory corruption. An attacker can send a malic...