CVE-2017-13721
- EPSS 0.09%
- Veröffentlicht 10.10.2017 01:30:21
- Zuletzt bearbeitet 29.08.2025 13:42:30
In X.Org Server (aka xserver and xorg-server) before 1.19.4, an attacker authenticated to an X server with the X shared memory extension enabled can cause aborts of the X server or replace shared memory segments of other X clients in the same session...
CVE-2017-13723
- EPSS 0.14%
- Veröffentlicht 10.10.2017 01:30:21
- Zuletzt bearbeitet 29.08.2025 13:42:30
In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing crashes of the X server or potentially other problems by injecting large or malformed XKB related atom...
CVE-2017-15041
- EPSS 7.17%
- Veröffentlicht 05.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. I...
CVE-2017-1000111
- EPSS 0.06%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...
CVE-2017-1000115
- EPSS 2.14%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository
- EPSS 5.38%
- Veröffentlicht 05.10.2017 01:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.
CVE-2017-14994
- EPSS 2.35%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames...
CVE-2017-14997
- EPSS 1.85%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
CVE-2017-12166
- EPSS 1.78%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.
CVE-2017-12617
- EPSS 94.36%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 22.10.2025 00:16:04
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...