CVE-2017-3167
- EPSS 10.35%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 04.11.2025 16:15:38
In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed.
CVE-2017-7668
- EPSS 66.38%
- Veröffentlicht 20.06.2017 01:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacke...
CVE-2017-1000366
- EPSS 7.62%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made t...
- EPSS 0.31%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note...
- EPSS 0.51%
- Veröffentlicht 19.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version...
CVE-2017-9373
- EPSS 0.1%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the AHCI device.
CVE-2017-9375
- EPSS 0.1%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users to cause a denial of service (infinite recursive call) via vectors involving control transfer descriptors sequencing.
CVE-2017-9503
- EPSS 0.07%
- Veröffentlicht 16.06.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving megasas co...
CVE-2017-9735
- EPSS 0.84%
- Veröffentlicht 16.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.
CVE-2017-4965
- EPSS 0.72%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior t...