- EPSS 0.08%
- Veröffentlicht 10.04.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.
CVE-2016-1516
- EPSS 0.76%
- Veröffentlicht 10.04.2017 03:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
CVE-2017-7608
- EPSS 0.46%
- Veröffentlicht 09.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7610
- EPSS 0.51%
- Veröffentlicht 09.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7611
- EPSS 0.51%
- Veröffentlicht 09.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7612
- EPSS 0.51%
- Veröffentlicht 09.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7613
- EPSS 0.61%
- Veröffentlicht 09.04.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CVE-2016-8735
- EPSS 93.97%
- Veröffentlicht 06.04.2017 21:59:00
- Zuletzt bearbeitet 22.10.2025 00:15:56
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because...
CVE-2014-5008
- EPSS 5.55%
- Veröffentlicht 31.03.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Snoopy allows remote attackers to execute arbitrary commands.
CVE-2017-6964
- EPSS 0.09%
- Veröffentlicht 28.03.2017 01:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) setuid or (2) setgid function, which might cause dmcrypt-get-device to execute code, which was intended to run as an unprivileged use...