CVE-2017-12865
- EPSS 3.76%
- Veröffentlicht 29.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.
CVE-2017-13737
- EPSS 1.83%
- Veröffentlicht 29.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.
CVE-2017-13748
- EPSS 2.66%
- Veröffentlicht 29.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
CVE-2017-3735
- EPSS 34.54%
- Veröffentlicht 28.08.2017 19:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of Op...
CVE-2017-12877
- EPSS 1.19%
- Veröffentlicht 28.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
CVE-2015-5146
- EPSS 2.36%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash...
CVE-2017-11424
- EPSS 1.3%
- Veröffentlicht 24.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format would be allowed because it is prefaced with the string `-----BEGIN RSA P...
CVE-2017-12135
- EPSS 0.13%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
CVE-2017-12136
- EPSS 0.05%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the host via vectors involving maptrack free list handling...
CVE-2017-12137
- EPSS 0.1%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.