CVE-2017-12607
- EPSS 0.63%
- Veröffentlicht 20.11.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary c...
CVE-2017-16899
- EPSS 0.43%
- Veröffentlicht 20.11.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the re...
CVE-2017-16544
- EPSS 3.31%
- Veröffentlicht 20.11.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the termin...
- EPSS 2.07%
- Veröffentlicht 17.11.2017 20:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVE-2017-16872
- EPSS 0.87%
- Veröffentlicht 17.11.2017 09:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing unintended values to be capture...
CVE-2017-1000158
- EPSS 3.59%
- Veröffentlicht 17.11.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
CVE-2017-1000229
- EPSS 0.36%
- Veröffentlicht 17.11.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
CVE-2017-16852
- EPSS 0.32%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as si...
CVE-2017-16853
- EPSS 0.69%
- Veröffentlicht 16.11.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as ...
CVE-2017-15864
- EPSS 0.5%
- Veröffentlicht 16.11.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.