CVE-2017-2620
- EPSS 2.41%
- Veröffentlicht 27.07.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:50
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use t...
CVE-2018-1056
- EPSS 0.42%
- Veröffentlicht 27.07.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:59:04
An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potentially use this flaw to crash the advzip utility by tricking it into processing crafted ZIP files.
CVE-2018-10882
- EPSS 0.06%
- Veröffentlicht 27.07.2018 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:13
A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.
- EPSS 0.11%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 29.08.2025 13:42:30
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations ret...
CVE-2017-2640
- EPSS 0.95%
- Veröffentlicht 27.07.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:53
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
CVE-2017-15119
- EPSS 1.55%
- Veröffentlicht 27.07.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:06
The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client ...
CVE-2017-15120
- EPSS 0.33%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:14:06
An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remot...
CVE-2017-2670
- EPSS 5.97%
- Veröffentlicht 27.07.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
CVE-2017-2666
- EPSS 1.39%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:56
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject...
CVE-2017-7519
- EPSS 0.04%
- Veröffentlicht 27.07.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:03
In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.