CVE-2017-5987
- EPSS 0.07%
- Veröffentlicht 20.03.2017 16:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local OS guest privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors involving the transfer mode register du...
CVE-2017-6831
- EPSS 4.52%
- Veröffentlicht 20.03.2017 16:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2017-6832
- EPSS 4.52%
- Veröffentlicht 20.03.2017 16:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2017-6834
- EPSS 6.9%
- Veröffentlicht 20.03.2017 16:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.
CVE-2017-6836
- EPSS 4.98%
- Veröffentlicht 20.03.2017 16:59:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash)...
CVE-2017-7178
- EPSS 1.23%
- Veröffentlicht 18.03.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable thi...
CVE-2017-6960
- EPSS 0.36%
- Veröffentlicht 17.03.2017 09:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function and the imagesize variable.
CVE-2017-5856
- EPSS 0.14%
- Veröffentlicht 16.03.2017 15:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sg...
CVE-2017-5617
- EPSS 1.08%
- Veröffentlicht 16.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct server-side request forgery (SSRF) attacks via an xlink:href attribute in an SVG file.
CVE-2017-5667
- EPSS 0.22%
- Veröffentlicht 16.03.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vecto...