Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 80 473

Количество 80 473

ubuntu логотип

CVE-2017-18214

больше 8 лет назад

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18212

больше 8 лет назад

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function in lit/lit-char-helpers.c via a RegExp("[\x0"); payload.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18211

больше 8 лет назад

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18210

больше 8 лет назад

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in MagickCore/opencl.c because a memory allocation result is not checked.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18209

больше 8 лет назад

In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18208

больше 8 лет назад

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18207

больше 8 лет назад

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18206

больше 8 лет назад

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18205

больше 8 лет назад

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-18204

больше 8 лет назад

The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of service (deadlock) via DIO requests.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18203

больше 8 лет назад

The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denial of service (BUG) by leveraging a race condition with __dm_destroy during creation and removal of DM devices.

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2017-18202

больше 8 лет назад

The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a copy_to_user call within a certain time window.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2017-18201

больше 8 лет назад

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18200

больше 8 лет назад

The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18199

больше 8 лет назад

realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18198

больше 8 лет назад

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18197

больше 8 лет назад

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-18196

больше 8 лет назад

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2017-18193

больше 8 лет назад

fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-18191

больше 8 лет назад

An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-18214

The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.

CVSS3: 7.5
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18212

An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function in lit/lit-char-helpers.c via a RegExp("[\x0"); payload.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18211

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function saveBinaryCLProgram in magick/opencl.c because a program-lookup result is not checked, related to CacheOpenCLKernel.

CVSS3: 9.8
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18210

In ImageMagick 7.0.7, a NULL pointer dereference vulnerability was found in the function BenchmarkOpenCLDevices in MagickCore/opencl.c because a memory allocation result is not checked.

CVSS3: 9.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18209

In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.

CVSS3: 8.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18208

The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18207

The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, which allows attackers to cause a denial of service (divide-by-zero and exception) via a crafted wav format audio file. NOTE: the vendor disputes this issue because Python applications "need to be prepared to handle a wide variety of exceptions.

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18206

In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18205

In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processing of the cd command with no argument if HOME is not set.

CVSS3: 8.1
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18204

The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of service (deadlock) via DIO requests.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18203

The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denial of service (BUG) by leveraging a race condition with __dm_destroy during creation and removal of DM devices.

CVSS3: 4.7
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18202

The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which allows attackers to cause a denial of service (TLB entry leak or use-after-free) or possibly have unspecified other impact by triggering a copy_to_user call within a certain time window.

CVSS3: 7
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18201

An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18200

The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demonstrated by fstrim.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18199

realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file.

CVSS3: 6.5
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18198

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file.

CVSS3: 8.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18197

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (XXE) attacks, as demonstrated by /ServerView.

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18196

Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp subdirectories, which might allow local users to bypass intended file restrictions by leveraging access to a directory located deeper within the /tmp directory tree, as demonstrated by /tmp/ANY/PATH/ANY/PATH/input.tif.

CVSS3: 3.3
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18193

fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a denial of service (BUG) via an application with multiple threads.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-18191

An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt the LUKS header, resulting in a denial of service attack on the compute host. (The same code error also results in data loss, but that is not a vulnerability because the user loses their own data.) All Nova setups supporting encrypted volumes are affected.

CVSS3: 7.5
4%
Низкий
больше 8 лет назад

Уязвимостей на страницу