CVE-2017-17083
- EPSS 0.92%
- Veröffentlicht 01.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.
CVE-2017-17084
- EPSS 0.92%
- Veröffentlicht 01.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.
CVE-2017-17085
- EPSS 10.4%
- Veröffentlicht 01.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.
CVE-2017-17087
- EPSS 0.16%
- Veröffentlicht 01.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an ...
CVE-2017-8816
- EPSS 0.44%
- Veröffentlicht 29.11.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via ...
CVE-2017-8817
- EPSS 0.61%
- Veröffentlicht 29.11.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
CVE-2017-14746
- EPSS 41.22%
- Veröffentlicht 27.11.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
CVE-2017-15275
- EPSS 45.21%
- Veröffentlicht 27.11.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
CVE-2017-14176
- EPSS 1.76%
- Veröffentlicht 27.11.2017 10:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-1622...
CVE-2017-8028
- EPSS 1.28%
- Veröffentlicht 27.11.2017 10:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy a...