Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 80 101

Количество 80 101

ubuntu логотип

CVE-2017-15932

почти 9 лет назад

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15931

почти 9 лет назад

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15930

почти 9 лет назад

In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15928

почти 9 лет назад

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15924

почти 9 лет назад

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15923

почти 9 лет назад

Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15922

почти 9 лет назад

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15914

больше 8 лет назад

Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15908

почти 9 лет назад

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2017-15906

почти 9 лет назад

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-15897

почти 9 лет назад

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2017-15896

почти 9 лет назад

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2017-15874

почти 9 лет назад

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

CVSS3: 5
EPSS: Низкий
ubuntu логотип

CVE-2017-15873

почти 9 лет назад

The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15868

почти 9 лет назад

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15864

почти 9 лет назад

In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15850

больше 8 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values from audio codec registers.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-15847

больше 8 лет назад

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the SPCom kernel driver, a race condition exists when creating a channel.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2017-15804

почти 9 лет назад

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-15736

почти 9 лет назад

Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-15932

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/format/elf/elf.c via crafted ELF files when parsing the ELF version on 32bit systems.

CVSS3: 7.8
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15931

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.

CVSS3: 7.8
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15930

In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.

CVSS3: 8.8
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15928

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication.

CVSS3: 7.5
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15924

In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.

CVSS3: 7.8
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15923

Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via vectors related to parsing of IRC color formatting codes.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15922

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15914

Incorrect implementation of access controls allows remote users to override repository restrictions in Borg servers 1.1.x before 1.1.3.

CVSS3: 8.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-15908

In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.

CVSS3: 7.5
24%
Средний
почти 9 лет назад
ubuntu логотип
CVE-2017-15906

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

CVSS3: 5.3
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15897

Node.js had a bug in versions 8.X and 9.X which caused buffers to not be initialized when the encoding for the fill value did not match the encoding specified. For example, 'Buffer.alloc(0x100, "This is not correctly encoded", "hex");' The buffer implementation was updated such that the buffer will be initialized to all zeros in these cases.

CVSS3: 3.1
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15896

Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application data to Node.js using the TLS or HTTP2 modules in a way that bypassed TLS authentication and encryption.

CVSS3: 9.1
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15874

archival/libarchive/decompress_unlzma.c in BusyBox 1.27.2 has an Integer Underflow that leads to a read access violation.

CVSS3: 5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15873

The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15868

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.

CVSS3: 7.8
0%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15864

In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.

CVSS3: 8.8
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15850

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values from audio codec registers.

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-15847

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the SPCom kernel driver, a race condition exists when creating a channel.

CVSS3: 7
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-15804

The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator.

CVSS3: 9.8
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-15736

Cross-site scripting (XSS) vulnerability (stored) in SPIP before 3.1.7 allows remote attackers to inject arbitrary web script or HTML via a crafted string, as demonstrated by a PGP field, related to prive/objets/contenu/auteur.html and ecrire/inc/texte_mini.php.

CVSS3: 6.1
1%
Низкий
почти 9 лет назад

Уязвимостей на страницу