CVE-2016-10510
- EPSS 0.67%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the Security component of Kohana before 3.3.6 allows remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php.
CVE-2017-0899
- EPSS 7.36%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
CVE-2017-0900
- EPSS 11.23%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
CVE-2017-0901
- EPSS 18.56%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
CVE-2017-0902
- EPSS 5.21%
- Veröffentlicht 31.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
CVE-2017-14064
- EPSS 1.21%
- Veröffentlicht 31.08.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning...
CVE-2017-14062
- EPSS 0.78%
- Veröffentlicht 31.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-14039
- EPSS 0.64%
- Veröffentlicht 30.08.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.
CVE-2017-14040
- EPSS 0.65%
- Veröffentlicht 30.08.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may lead to remote denial of service or possibly unspecified other impact.
CVE-2017-14041
- EPSS 0.91%
- Veröffentlicht 30.08.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.