Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2017-10972

около 9 лет назад

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2017-10971

около 9 лет назад

In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2017-10966

около 9 лет назад

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2017-10965

около 9 лет назад

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2017-10928

около 9 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-10923

около 9 лет назад

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2017-10922

около 9 лет назад

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10921

около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10920

около 9 лет назад

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10919

около 9 лет назад

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

CVSS3: 7.7
EPSS: Низкий
redhat логотип

CVE-2017-10918

около 9 лет назад

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10917

около 9 лет назад

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10916

около 9 лет назад

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2017-10915

около 9 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10914

около 9 лет назад

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10913

около 9 лет назад

The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10912

около 9 лет назад

Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2017-10911

около 9 лет назад

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2017-10906

почти 9 лет назад

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-10810

больше 9 лет назад

Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

CVSS3: 4.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-10972

Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.

CVSS3: 6.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10971

In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events.

CVSS3: 4.7
4%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10966

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.

CVSS3: 4.8
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10965

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS3: 3.7
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10928

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 3.3
4%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10923

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

CVSS3: 7.7
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10922

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

CVSS3: 8.5
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10921

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 8.5
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10920

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.

CVSS3: 8.5
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10919

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

CVSS3: 7.7
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10918

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

CVSS3: 8.5
4%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10917

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

CVSS3: 8.5
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10916

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

CVSS3: 8
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10915

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 8.5
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10914

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

CVSS3: 8.5
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10913

The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

CVSS3: 8.5
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10912

Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

CVSS3: 8.5
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

CVSS3: 3
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-10906

Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.

CVSS3: 5.3
5%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-10810

Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

CVSS3: 4.1
4%
Низкий
больше 9 лет назад

Уязвимостей на страницу