CVE-2017-7746
- EPSS 2.05%
- Veröffentlicht 12.04.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the SLSK dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-slsk.c by adding checks for the remaining leng...
CVE-2017-7747
- EPSS 2.05%
- Veröffentlicht 12.04.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-packetbb.c by restricting additions to the protocol tree.
CVE-2017-7697
- EPSS 0.43%
- Veröffentlicht 11.04.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.
CVE-2015-8504
- EPSS 2.81%
- Veröffentlicht 11.04.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) via crafted SetPixelFormat messages from a client.
CVE-2015-8568
- EPSS 0.06%
- Veröffentlicht 11.04.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host memory consumption) by trying to activate the vmxnet3 device repeatedly.
CVE-2015-8613
- EPSS 0.1%
- Veröffentlicht 11.04.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local guest users to cause a denial of service (QEMU instance crash) via a crafted SCSI controller CTRL_GET_INF...
CVE-2015-8666
- EPSS 0.08%
- Veröffentlicht 11.04.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.
CVE-2016-1908
- EPSS 2.18%
- Veröffentlicht 11.04.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding...
CVE-2016-5322
- EPSS 0.18%
- Veröffentlicht 11.04.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.
CVE-2016-4483
- EPSS 1.27%
- Veröffentlicht 11.04.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulne...