Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2017-1000231

больше 9 лет назад

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2017-1000229

больше 8 лет назад

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-1000211

больше 8 лет назад

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-1000201

около 9 лет назад

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-1000200

около 9 лет назад

tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-1000199

около 9 лет назад

tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-1000198

около 9 лет назад

tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-1000189

больше 9 лет назад

nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2017-1000188

больше 9 лет назад

nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2017-1000159

около 9 лет назад

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2017-1000158

около 9 лет назад

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2017-1000128

около 9 лет назад

Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-1000127

около 9 лет назад

Exiv2 0.26 contains a heap buffer overflow in tiff parser

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-1000126

около 9 лет назад

exiv2 0.26 contains a Stack out of bounds read in webp parser

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-1000117

около 9 лет назад

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 6.3
EPSS: Высокий
redhat логотип

CVE-2017-1000116

около 9 лет назад

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2017-1000115

около 9 лет назад

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2017-1000112

около 9 лет назад

Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.

CVSS3: 7
EPSS: Средний
redhat логотип

CVE-2017-1000111

около 9 лет назад

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2017-1000108

около 9 лет назад

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-1000231

A double-free vulnerability in parse.c in ldns 1.7.0 have unspecified impact and attack vectors.

CVSS3: 7
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-1000229

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

CVSS3: 3.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-1000211

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

CVSS3: 5.3
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-1000201

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

CVSS3: 5.5
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000200

tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a dbus triggered NULL pointer dereference in the tcmu-runner daemon's on_unregister_handler() function resulting in denial of service

CVSS3: 5.5
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000199

tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000198

tcmu-runner daemon version 0.9.0 to 1.2.0 is vulnerable to invalid memory references in the handler_glfs.so handler resulting in denial of service

CVSS3: 5.5
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000189

nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()

CVSS3: 4.7
2%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-1000188

nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection

CVSS3: 6.1
1%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-1000159

Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91.

CVSS3: 7.8
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000158

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

CVSS3: 8.1
8%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000128

Exiv2 0.26 contains a stack out of bounds read in JPEG2000 parser

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000127

Exiv2 0.26 contains a heap buffer overflow in tiff parser

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000126

exiv2 0.26 contains a Stack out of bounds read in webp parser

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000117

A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any program that exists on the victim's machine being executed. Such a URL could be placed in the .gitmodules file of a malicious project, and an unsuspecting victim could be tricked into running "git clone --recurse-submodules" to trigger the vulnerability.

CVSS3: 6.3
78%
Высокий
около 9 лет назад
redhat логотип
CVE-2017-1000116

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

CVSS3: 6.3
6%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000115

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

CVSS3: 5.4
5%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000112

Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE __ip_append_data() calls ip_ufo_append_data() to append. However in between two send() calls, the append path can be switched from UFO to non-UFO one, which leads to a memory corruption. In case UFO packet lengths exceeds MTU, copy = maxfraglen - skb->len becomes negative on the non-UFO path and the branch to allocate new skb is taken. This triggers fragmentation and computation of fraggap = skb_prev->len - maxfraglen. Fraggap can exceed MTU, causing copy = datalen - transhdrlen - fraggap to become negative. Subsequently skb_copy_and_csum_bits() writes out-of-bounds. A similar issue is present in IPv6 code. The bug was introduced in e89e9cf539a2 ("[IPv4/IPv6]: UFO Scatter-gather approach") on Oct 18 2005.

CVSS3: 7
21%
Средний
около 9 лет назад
redhat логотип
CVE-2017-1000111

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_VERSION. This time with PACKET_RESERVE. The solution is similar: lock the socket for the update. This issue may be exploitable, we did not investigate further. As this issue affects PF_PACKET sockets, it requires CAP_NET_RAW in the process namespace. But note that with user namespaces enabled, any process can create a namespace in which it has CAP_NET_RAW.

CVSS3: 4.7
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-1000108

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has been changed, and now requires users to have the Item/Build permission instead.

CVSS3: 4.3
1%
Низкий
около 9 лет назад

Уязвимостей на страницу