CVE-2017-17856
- EPSS 0.13%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the lack of stack-pointer alignment enforcement.
CVE-2017-17857
- EPSS 0.13%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of invalid variable ...
CVE-2017-17862
- EPSS 0.08%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 ignores unreachable code, even though it would still be processed by JIT compilers. This behavior, also considered an improper branch-pruning logic issue, could possibly be used by local users ...
CVE-2017-17863
- EPSS 0.09%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows local users to cause a denial of service (integer overflow or invalid memory access) or possibly hav...
CVE-2017-17864
- EPSS 0.09%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 mishandles states_equal comparisons between the pointer data type and the UNKNOWN_VALUE data type, which allows local users to obtain potentially sensitive address information, aka a "pointer l...
CVE-2017-17866
- EPSS 0.15%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 13.05.2026 00:24:29
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly h...
CVE-2017-17843
- EPSS 0.2%
- Veröffentlicht 27.12.2017 17:08:19
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Enigmail before 1.9.9 that allows remote attackers to trigger use of an intended public key for encryption, because incorrect regular expressions are used for extraction of an e-mail address from a comma-separated list, as ...
CVE-2017-17844
- EPSS 0.24%
- Veröffentlicht 27.12.2017 17:08:19
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Enigmail before 1.9.9. A remote attacker can obtain cleartext content by sending an encrypted data block (that the attacker cannot directly decrypt) to a victim, and relying on the victim to automatically decrypt that block...
CVE-2017-17845
- EPSS 0.51%
- Veröffentlicht 27.12.2017 17:08:19
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Enigmail before 1.9.9. Improper Random Secret Generation occurs because Math.Random() is used by pretty Easy privacy (pEp), aka TBE-01-001.
CVE-2017-17846
- EPSS 0.78%
- Veröffentlicht 27.12.2017 17:08:19
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Enigmail before 1.9.9. Regular expressions are exploitable for Denial of Service, because of attempts to match arbitrarily long strings, aka TBE-01-003.