CVE-2017-9461
- EPSS 3.38%
- Veröffentlicht 06.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.
- EPSS 48.7%
- Veröffentlicht 06.06.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.
CVE-2015-1207
- EPSS 0.46%
- Veröffentlicht 06.06.2017 18:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Double-free vulnerability in libavformat/mov.c in FFMPEG in Google Chrome 41.0.2251.0 allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted .m4a file.
CVE-2017-9403
- EPSS 0.51%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9404
- EPSS 0.51%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9406
- EPSS 1.05%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9408
- EPSS 1.05%
- Veröffentlicht 02.06.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9344
- EPSS 1.18%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.
CVE-2017-9349
- EPSS 0.81%
- Veröffentlicht 02.06.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.
CVE-2017-6512
- EPSS 1.38%
- Veröffentlicht 01.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.