CVE-2017-9780
- EPSS 0.11%
- Veröffentlicht 21.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacke...
CVE-2017-9766
- EPSS 0.89%
- Veröffentlicht 21.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.
CVE-2017-3167
- EPSS 10.35%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 04.11.2025 16:15:38
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
CVE-2017-7668
- EPSS 64.41%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...
CVE-2017-1000366
- EPSS 8.16%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...
- EPSS 0.31%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note...
- EPSS 0.42%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version...
CVE-2017-9373
- EPSS 0.1%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device.
CVE-2017-9375
- EPSS 0.1%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
CVE-2017-9503
- EPSS 0.07%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas co...