CVE-2017-9344
- EPSS 1.18%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.
CVE-2017-9349
- EPSS 0.81%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.
CVE-2017-6512
- EPSS 0.9%
- Veröffentlicht 01.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.
CVE-2017-8386
- EPSS 72.73%
- Veröffentlicht 01.06.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain pr...
- EPSS 94.25%
- Veröffentlicht 30.05.2017 18:29:00
- Zuletzt bearbeitet 22.10.2025 00:16:11
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
CVE-2017-9287
- EPSS 38.97%
- Veröffentlicht 29.05.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
CVE-2015-5211
- EPSS 1.88%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch scrip...
CVE-2017-9216
- EPSS 1.43%
- Veröffentlicht 24.05.2017 05:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid f...
CVE-2017-8312
- EPSS 0.34%
- Veröffentlicht 23.05.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
CVE-2017-8314
- EPSS 6.92%
- Veröffentlicht 23.05.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.