CVE-2017-6308
- EPSS 0.4%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.
CVE-2017-6309
- EPSS 0.44%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.
CVE-2017-6310
- EPSS 0.35%
- Veröffentlicht 24.02.2017 04:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.
CVE-2016-1245
- EPSS 1.19%
- Veröffentlicht 22.02.2017 23:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BU...
CVE-2017-6188
- EPSS 0.14%
- Veröffentlicht 22.02.2017 19:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
CVE-2016-9956
- EPSS 1.89%
- Veröffentlicht 22.02.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
CVE-2017-6074
- EPSS 20.04%
- Veröffentlicht 18.02.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double...
CVE-2017-6014
- EPSS 0.42%
- Veröffentlicht 17.02.2017 07:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attem...
CVE-2017-6056
- EPSS 13.83%
- Veröffentlicht 17.02.2017 07:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backportin...
CVE-2016-9955
- EPSS 0.41%
- Veröffentlicht 17.02.2017 02:59:14
- Zuletzt bearbeitet 13.05.2026 00:24:29
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return...