CVE-2017-1000407
- EPSS 0.46%
- Veröffentlicht 11.12.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
CVE-2017-17499
- EPSS 2.03%
- Veröffentlicht 11.12.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
CVE-2017-17504
- EPSS 0.98%
- Veröffentlicht 11.12.2017 02:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.
CVE-2017-17480
- EPSS 3.92%
- Veröffentlicht 08.12.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.
CVE-2017-13168
- EPSS 0.17%
- Veröffentlicht 06.12.2017 14:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
CVE-2017-15868
- EPSS 0.07%
- Veröffentlicht 05.12.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.
CVE-2016-1252
- EPSS 5.96%
- Veröffentlicht 05.12.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 before 1.3.2ubuntu0.1 allows man-in-the-middle attacke...
CVE-2017-16611
- EPSS 0.06%
- Veröffentlicht 01.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
CVE-2017-16612
- EPSS 3.56%
- Veröffentlicht 01.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcur...
CVE-2017-17087
- EPSS 0.16%
- Veröffentlicht 01.12.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an ...