CVE-2017-16876
- EPSS 0.58%
- Veröffentlicht 29.12.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
CVE-2017-16818
- EPSS 0.59%
- Veröffentlicht 20.12.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, r...
CVE-2016-1254
- EPSS 3.04%
- Veröffentlicht 05.12.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
CVE-2015-5739
- EPSS 19.21%
- Veröffentlicht 18.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" ...
CVE-2015-5740
- EPSS 5.69%
- Veröffentlicht 18.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
CVE-2015-7687
- EPSS 10.14%
- Veröffentlicht 16.10.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
CVE-2014-9092
- EPSS 1.87%
- Veröffentlicht 10.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
CVE-2017-13704
- EPSS 81.76%
- Veröffentlicht 03.10.2017 01:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platf...
CVE-2015-5069
- EPSS 0.67%
- Veröffentlicht 26.09.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors rel...
CVE-2015-5070
- EPSS 0.66%
- Veröffentlicht 26.09.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to...