Количество 24 658
Количество 24 658
CVE-2017-6828
Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact
CVE-2017-6827
Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact via a crafted audio file
CVE-2017-6519
CVE-2017-5974
Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
CVE-2017-5931
CVE-2017-5836
The plist_free_data function libplist allows attackers to cause a denial of service
CVE-2017-5835
libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.
CVE-2017-5834
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service
CVE-2017-3736
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.
CVE-2017-3735
CVE-2017-3731
Truncated packet could crash via OOB read
CVE-2017-3617
CVE-2017-3616
CVE-2017-3615
CVE-2017-3614
CVE-2017-3613
CVE-2017-3612
CVE-2017-3611
CVE-2017-3610
CVE-2017-3609
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-6828 Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact | CVSS3: 7.8 | 3% Низкий | 10 месяцев назад | |
CVE-2017-6827 Heap-based buffer overflow in audiofile allows remote attackers to have unspecified impact via a crafted audio file | CVSS3: 7.8 | 3% Низкий | 10 месяцев назад | |
CVSS3: 9.1 | 3% Низкий | больше 4 лет назад | ||
CVE-2017-5974 Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file. | CVSS3: 5.5 | 2% Низкий | около 1 года назад | |
CVSS3: 8.8 | 1% Низкий | почти 6 лет назад | ||
CVE-2017-5836 The plist_free_data function libplist allows attackers to cause a denial of service | CVSS3: 7.5 | 3% Низкий | 10 месяцев назад | |
CVE-2017-5835 libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. | CVSS3: 7.5 | 3% Низкий | 10 месяцев назад | |
CVE-2017-5834 The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service | CVSS3: 5.5 | 1% Низкий | 10 месяцев назад | |
CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen. | 10% Средний | 3 месяца назад | ||
18% Средний | 3 месяца назад | |||
CVE-2017-3731 Truncated packet could crash via OOB read | 58% Средний | 3 месяца назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад | ||
CVSS3: 7 | 0% Низкий | около 5 лет назад |
Уязвимостей на страницу