CVE-2017-14491
- EPSS 60.19%
- Veröffentlicht 04.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CVE-2017-14990
- EPSS 0.38%
- Veröffentlicht 03.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database rea...
CVE-2017-14492
- EPSS 92.64%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
CVE-2017-14493
- EPSS 5.62%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
CVE-2017-14494
- EPSS 13.05%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
CVE-2017-14495
- EPSS 60.15%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.
CVE-2017-14496
- EPSS 15.74%
- Veröffentlicht 03.10.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
CVE-2017-13704
- EPSS 81.76%
- Veröffentlicht 03.10.2017 01:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platf...
CVE-2017-14975
- EPSS 1.1%
- Veröffentlicht 02.10.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is not initialized, which allows an attacker to launch a denial of service attack.
CVE-2017-14976
- EPSS 1.09%
- Veröffentlicht 02.10.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.