CVE-2017-6305
- EPSS 0.23%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."
CVE-2017-6306
- EPSS 0.59%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal using the filename; SanitizeFilename function in settings.c."
CVE-2017-6307
- EPSS 0.41%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.
CVE-2017-6308
- EPSS 0.28%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
CVE-2017-6309
- EPSS 0.41%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
CVE-2017-6310
- EPSS 0.35%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
CVE-2016-1245
- EPSS 1.19%
- Veröffentlicht 22.02.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BU...
CVE-2017-6188
- EPSS 0.14%
- Veröffentlicht 22.02.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
CVE-2016-9956
- EPSS 1.89%
- Veröffentlicht 22.02.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
CVE-2017-6074
- EPSS 21.55%
- Veröffentlicht 18.02.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double...