CVE-2017-8386
- EPSS 73.29%
- Veröffentlicht 01.06.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain pr...
- EPSS 94.18%
- Veröffentlicht 30.05.2017 18:29:00
- Zuletzt bearbeitet 21.04.2026 19:36:42
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it.
CVE-2017-9287
- EPSS 26.53%
- Veröffentlicht 29.05.2017 16:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
servers/slapd/back-mdb/search.c in OpenLDAP through 2.4.44 is prone to a double free vulnerability. A user with access to search the directory can crash slapd by issuing a search including the Paged Results control with a page size of 0.
CVE-2015-5211
- EPSS 1.92%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch scrip...
CVE-2017-9216
- EPSS 0.89%
- Veröffentlicht 24.05.2017 05:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid f...
CVE-2017-8312
- EPSS 0.34%
- Veröffentlicht 23.05.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a crafted subtitles file.
CVE-2017-8314
- EPSS 2.52%
- Veröffentlicht 23.05.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.
CVE-2017-9214
- EPSS 4.37%
- Veröffentlicht 23.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
CVE-2017-8309
- EPSS 1.11%
- Veröffentlicht 23.05.2017 04:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
CVE-2017-8379
- EPSS 0.08%
- Veröffentlicht 23.05.2017 04:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Memory leak in the keyboard input event handlers support in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) by rapidly generating large keyboard events.