CVE-2016-4000
- EPSS 12.49%
- Veröffentlicht 06.07.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
CVE-2017-9524
- EPSS 4.16%
- Veröffentlicht 06.07.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initi...
CVE-2017-2295
- EPSS 1.89%
- Veröffentlicht 05.07.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code...
CVE-2017-10810
- EPSS 0.83%
- Veröffentlicht 04.07.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.
CVE-2017-10672
- EPSS 10.05%
- Veröffentlicht 29.06.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
CVE-2017-9988
- EPSS 0.63%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.
CVE-2017-9989
- EPSS 0.63%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.
CVE-2017-9992
- EPSS 0.7%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application c...
CVE-2017-9993
- EPSS 56.17%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist d...
CVE-2017-9994
- EPSS 0.42%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow ...