CVE-2017-11521
- EPSS 1.63%
- Veröffentlicht 22.07.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections.
CVE-2015-5194
- EPSS 8.41%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
CVE-2015-5195
- EPSS 7.93%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
CVE-2015-5219
- EPSS 2.24%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
CVE-2015-5300
- EPSS 36.84%
- Veröffentlicht 21.07.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option,...
CVE-2017-11450
- EPSS 0.4%
- Veröffentlicht 19.07.2017 07:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.
CVE-2017-11406
- EPSS 0.81%
- Veröffentlicht 18.07.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS dissector could go into an infinite loop. This was addressed in plugins/docsis/packet-docsis.c by rejecting invalid Frame Control parameter values.
CVE-2017-11407
- EPSS 1.19%
- Veröffentlicht 18.07.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fragment length before a reassembly attempt.
CVE-2017-11409
- EPSS 1.19%
- Veröffentlicht 18.07.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.0.0 to 2.0.13, the GPRS LLC dissector could go into a large loop. This was addressed in epan/dissectors/packet-gprs-llc.c by using a different integer data type.
CVE-2017-10978
- EPSS 2.58%
- Veröffentlicht 17.07.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.