CVE-2017-4967
- EPSS 0.51%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these RabbitMQ for PCF versions: all 1.5.x versions, 1.6.x versions prior to 1.6.18, and 1.7.x versions prior t...
CVE-2017-9324
- EPSS 1.36%
- Veröffentlicht 12.06.2017 06:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all...
CVE-2017-9527
- EPSS 0.2%
- Veröffentlicht 11.06.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based use-after-free and application crash) or possibly have unspecified other impact via a crafted .rb file.
CVE-2017-0376
- EPSS 0.82%
- Veröffentlicht 09.06.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connection_edge_process_relay_cell function via a BEGIN_DIR cell on a rendezvous circuit.
CVE-2017-9525
- EPSS 0.06%
- Veröffentlicht 09.06.2017 16:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
CVE-2017-9022
- EPSS 0.86%
- Veröffentlicht 08.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause a denial of service (floating point exception and process crash) via a crafted certificate.
CVE-2017-9310
- EPSS 0.09%
- Veröffentlicht 08.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
QEMU (aka Quick Emulator), when built with the e1000e NIC emulation support, allows local guest OS privileged users to cause a denial of service (infinite loop) via vectors related to setting the initial receive / transmit descriptor head (TDH/RDH) o...
CVE-2017-9330
- EPSS 0.05%
- Veröffentlicht 08.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
QEMU (aka Quick Emulator) before 2.9.0, when built with the USB OHCI Emulation support, allows local guest OS users to cause a denial of service (infinite loop) by leveraging an incorrect return value, a different vulnerability than CVE-2017-6505.
CVE-2017-9468
- EPSS 0.85%
- Veröffentlicht 07.06.2017 01:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Irssi before 1.0.3, when receiving a DCC message without source nick/host, it attempts to dereference a NULL pointer. Thus, remote IRC servers can cause a crash.
CVE-2017-9469
- EPSS 1.4%
- Veröffentlicht 07.06.2017 01:29:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memory. Thus, remote attackers might be able to cause a crash.