CVE-2017-10978
- EPSS 3.31%
- Veröffentlicht 17.07.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
CVE-2017-11352
- EPSS 0.98%
- Veröffentlicht 17.07.2017 13:18:21
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
CVE-2017-1000363
- EPSS 0.54%
- Veröffentlicht 17.07.2017 13:18:18
- Zuletzt bearbeitet 20.04.2025 01:37:25
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, wher...
CVE-2017-9788
- EPSS 52.64%
- Veröffentlicht 13.07.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-11103
- EPSS 6.3%
- Veröffentlicht 13.07.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name ...
CVE-2017-11173
- EPSS 1.75%
- Veröffentlicht 13.07.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain n...
CVE-2017-11176
- EPSS 16.14%
- Veröffentlicht 11.07.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possi...
CVE-2017-11139
- EPSS 0.47%
- Veröffentlicht 10.07.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
CVE-2017-11107
- EPSS 0.12%
- Veröffentlicht 08.07.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
CVE-2017-11104
- EPSS 1.98%
- Veröffentlicht 08.07.2017 10:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of ...