Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 926

Количество 79 926

ubuntu логотип

CVE-2017-14926

почти 9 лет назад

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14919

почти 9 лет назад

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14868

почти 9 лет назад

Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14867

почти 9 лет назад

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2017-14866

почти 9 лет назад

There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14865

почти 9 лет назад

There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14864

почти 9 лет назад

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14863

почти 9 лет назад

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14862

почти 9 лет назад

An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14861

почти 9 лет назад

There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14860

почти 9 лет назад

There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14859

почти 9 лет назад

An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14858

почти 9 лет назад

There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14857

почти 9 лет назад

In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-14849

почти 9 лет назад

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2017-14804

больше 8 лет назад

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

CVSS3: 9.9
EPSS: Низкий
ubuntu логотип

CVE-2017-14798

больше 8 лет назад

A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2017-14767

почти 9 лет назад

The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other impact via a crafted sdp file.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-14749

почти 9 лет назад

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-14746

почти 9 лет назад

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-14926

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14919

Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.

CVSS3: 7.5
8%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14868

Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14867

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacharacters in a module name. The vulnerable code is reachable via git-shell even without CVS support.

CVSS3: 8.8
36%
Средний
почти 9 лет назад
ubuntu логотип
CVE-2017-14866

There is a heap-based buffer overflow in the Exiv2::s2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14865

There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14864

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14863

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14862

An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14861

There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14860

There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14859

An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14858

There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14857

In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14849

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

CVSS3: 7.5
54%
Средний
почти 9 лет назад
ubuntu логотип
CVE-2017-14804

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.

CVSS3: 9.9
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14798

A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

CVSS3: 7.3
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-14767

The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (heap buffer overflow) or possibly have unspecified other impact via a crafted sdp file.

CVSS3: 8.8
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14749

JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecognized \ characters cause incorrect 0x00 characters in bytecode.literal data.

CVSS3: 7.8
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-14746

Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.

CVSS3: 9.8
10%
Низкий
почти 9 лет назад

Уязвимостей на страницу