Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 897

Количество 54 897

redhat логотип

CVE-2017-6458

больше 9 лет назад

Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2017-6455

больше 9 лет назад

NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2017-6452

больше 9 лет назад

Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via an application path on the command line.

CVSS3: 1.8
EPSS: Низкий
redhat логотип

CVE-2017-6451

больше 9 лет назад

The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2017-6441

больше 9 лет назад

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-6440

больше 9 лет назад

The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6439

больше 9 лет назад

Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6438

больше 9 лет назад

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6437

больше 9 лет назад

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6436

больше 9 лет назад

The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6435

больше 9 лет назад

The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-6419

больше 9 лет назад

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2017-6414

больше 9 лет назад

Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2017-6413

больше 9 лет назад

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2017-6410

больше 9 лет назад

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-6362

почти 9 лет назад

Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-6353

больше 9 лет назад

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-6350

больше 9 лет назад

An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

CVSS3: 2.5
EPSS: Низкий
redhat логотип

CVE-2017-6349

больше 9 лет назад

An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

CVSS3: 2.5
EPSS: Низкий
redhat логотип

CVE-2017-6348

больше 9 лет назад

The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.

CVSS3: 6.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-6458

Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.

CVSS3: 7.1
7%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6455

NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.

CVSS3: 4
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6452

Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via an application path on the command line.

CVSS3: 1.8
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6451

The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which trigger an out-of-bounds memory write.

CVSS3: 7
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6441

The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted use of "declare(ticks=" in a PHP script. NOTE: the vendor disputes the classification of this as a vulnerability, stating "Please do not request CVEs for ordinary bugs. CVEs are relevant for security issues only.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6440

The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

CVSS3: 3.3
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6439

Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.

CVSS3: 3.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6438

Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.

CVSS3: 3.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6437

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

CVSS3: 3.3
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6436

The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.

CVSS3: 3.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6435

The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.

CVSS3: 3.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6419

mspack/lzxd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted CHM file.

CVSS3: 6.5
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6414

Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.

CVSS3: 3
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6413

The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.

CVSS3: 5.9
4%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6410

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.

CVSS3: 5.3
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6362

Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.

CVSS3: 5.3
5%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-6353

net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6350

An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

CVSS3: 2.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6349

An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

CVSS3: 2.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-6348

The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.

CVSS3: 6.2
0%
Низкий
больше 9 лет назад

Уязвимостей на страницу