CVE-2017-11352
- EPSS 0.98%
- Veröffentlicht 17.07.2017 13:18:21
- Zuletzt bearbeitet 13.05.2026 00:24:29
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
CVE-2017-1000363
- EPSS 0.54%
- Veröffentlicht 17.07.2017 13:18:18
- Zuletzt bearbeitet 13.05.2026 00:24:29
Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, wher...
CVE-2017-9788
- EPSS 49.5%
- Veröffentlicht 13.07.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial ke...
CVE-2017-11103
- EPSS 5.28%
- Veröffentlicht 13.07.2017 13:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name ...
CVE-2017-11173
- EPSS 1.75%
- Veröffentlicht 13.07.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain n...
CVE-2017-11176
- EPSS 20.81%
- Veröffentlicht 11.07.2017 23:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retry logic. During a user-space close of a Netlink socket, it allows attackers to cause a denial of service (use-after-free) or possi...
CVE-2017-11139
- EPSS 0.47%
- Veröffentlicht 10.07.2017 03:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
CVE-2017-11107
- EPSS 0.12%
- Veröffentlicht 08.07.2017 12:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
CVE-2017-11104
- EPSS 1.98%
- Veröffentlicht 08.07.2017 10:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of ...
CVE-2016-4000
- EPSS 12.49%
- Veröffentlicht 06.07.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.