CVE-2017-14604
- EPSS 3.91%
- Veröffentlicht 20.09.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command....
CVE-2015-1854
- EPSS 1.63%
- Veröffentlicht 19.09.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
CVE-2017-9798
- EPSS 93.84%
- Veröffentlicht 18.09.2017 15:29:00
- Zuletzt bearbeitet 04.11.2025 16:15:41
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user's .htaccess file, or if httpd.conf has certain misconfigurations, aka Optionsbleed. This affects the Apache HTTP Server through 2...
CVE-2017-14528
- EPSS 0.78%
- Veröffentlicht 18.09.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply that data validation has occurred, which allows remote attackers to cause a denial of service (use-af...
CVE-2017-14504
- EPSS 1%
- Veröffentlicht 17.09.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer Dereference.
CVE-2017-14497
- EPSS 0.07%
- Veröffentlicht 15.09.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might allow local users to cause a denial of service (buffer overflow, and disk and memory corruption) or possibly have unspecified othe...
CVE-2017-14482
- EPSS 4.58%
- Veröffentlicht 14.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched exten...
CVE-2017-13687
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:03
- Zuletzt bearbeitet 04.12.2025 15:15:52
The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
CVE-2017-13725
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
CVE-2017-13024
- EPSS 2.06%
- Veröffentlicht 14.09.2017 06:29:02
- Zuletzt bearbeitet 04.12.2025 16:16:12
The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().