CVE-2017-5617
- EPSS 1.08%
- Veröffentlicht 16.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
CVE-2017-5667
- EPSS 0.16%
- Veröffentlicht 16.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vecto...
CVE-2016-10246
- EPSS 0.29%
- Veröffentlicht 16.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Buffer overflow in the main function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
CVE-2016-10247
- EPSS 0.31%
- Veröffentlicht 16.03.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Buffer overflow in the my_getline function in jstest_main.c in Mujstest in Artifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.
CVE-2016-7103
- EPSS 1.38%
- Veröffentlicht 15.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
CVE-2017-5522
- EPSS 4.84%
- Veröffentlicht 15.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving WFS get feature request...
- EPSS 0.1%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CVE-2016-10195
- EPSS 3.97%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack read.
CVE-2016-10196
- EPSS 0.81%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string ar...
CVE-2016-10197
- EPSS 1.86%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.