Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-12978

около 9 лет назад

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2017-12976

около 9 лет назад

git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12967

около 9 лет назад

The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12966

около 9 лет назад

The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12964

около 9 лет назад

There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12963

около 9 лет назад

There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12962

около 9 лет назад

There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, leading to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12961

около 9 лет назад

There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12960

около 9 лет назад

There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12959

около 9 лет назад

There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12958

около 9 лет назад

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12957

около 9 лет назад

There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to remote denial of service.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12956

около 9 лет назад

There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12955

около 9 лет назад

There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26. The vulnerability causes an out-of-bounds write in Exiv2::Image::printIFDStructure(), which may lead to remote denial of service or possibly unspecified other impact.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12954

около 9 лет назад

The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12953

около 9 лет назад

The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12952

около 9 лет назад

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12951

около 9 лет назад

The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12950

около 9 лет назад

The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12944

около 9 лет назад

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-12978

lib/html.php in Cacti before 1.1.18 has XSS via the title field of an external link added by an authenticated user.

CVSS3: 5.4
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12976

git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as demonstrated by an ssh://-eProxyCommand= URL, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-1000116, and CVE-2017-1000117.

CVSS3: 8.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12967

The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.

CVSS3: 6.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12966

The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted .asn1 file.

CVSS3: 6.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12964

There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12963

There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this is similar to CVE-2017-11555 but remains exploitable after the vendor's CVE-2017-11555 fix (available from GitHub after 2017-07-24).

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12962

There are memory leaks in LibSass 3.4.5 triggered by deeply nested code, such as code with a long sequence of open parenthesis characters, leading to a remote denial of service attack.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12961

There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12960

There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12959

There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12958

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12957

There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to remote denial of service.

CVSS3: 6.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12956

There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of service.

CVSS3: 6.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12955

There is a heap-based buffer overflow in basicio.cpp of Exiv2 0.26. The vulnerability causes an out-of-bounds write in Exiv2::Image::printIFDStructure(), which may lead to remote denial of service or possibly unspecified other impact.

CVSS3: 8.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12954

The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file.

CVSS3: 6.5
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12953

The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted gig file.

CVSS3: 6.5
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12952

The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12951

The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted gig file.

CVSS3: 6.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12950

The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted gig file.

CVSS3: 6.5
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12944

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to cause a denial of service (allocation failure and application crash) in the TIFFFetchStripThing function in tif_dirread.c during a tiff2pdf invocation.

CVSS3: 7.5
3%
Низкий
около 9 лет назад

Уязвимостей на страницу