CVE-2017-11407
- EPSS 1.19%
- Veröffentlicht 18.07.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.
CVE-2017-11409
- EPSS 1.19%
- Veröffentlicht 18.07.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
CVE-2017-10978
- EPSS 3.31%
- Veröffentlicht 17.07.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
CVE-2017-11352
- EPSS 0.98%
- Veröffentlicht 17.07.2017 13:18:21
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
CVE-2017-1000363
- EPSS 0.54%
- Veröffentlicht 17.07.2017 13:18:18
- Zuletzt bearbeitet 20.04.2025 01:37:25
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, wher...
CVE-2017-9788
- EPSS 52.64%
- Veröffentlicht 13.07.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-11103
- EPSS 6.22%
- Veröffentlicht 13.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name ...
CVE-2017-11173
- EPSS 1.75%
- Veröffentlicht 13.07.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain n...
CVE-2017-11176
- EPSS 16.14%
- Veröffentlicht 11.07.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possi...
CVE-2017-11139
- EPSS 0.47%
- Veröffentlicht 10.07.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.