Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-12897

около 9 лет назад

The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12896

около 9 лет назад

The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12895

около 9 лет назад

The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12894

около 9 лет назад

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12893

около 9 лет назад

The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12883

около 9 лет назад

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2017-12877

около 9 лет назад

Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12876

около 9 лет назад

Heap-based buffer overflow in enhance.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12875

около 9 лет назад

The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU consumption) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12874

около 9 лет назад

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12873

около 9 лет назад

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12872

около 9 лет назад

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-12871

около 9 лет назад

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-12870

около 9 лет назад

SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-12869

около 9 лет назад

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-12868

около 9 лет назад

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12867

около 9 лет назад

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-12865

около 9 лет назад

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12864

около 9 лет назад

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-12863

около 9 лет назад

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-12897

The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12896

The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12895

The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12894

Several protocol parsers in tcpdump before 4.9.2 could cause a buffer over-read in addrtoname.c:lookup_bytestring().

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12893

The SMB/CIFS parser in tcpdump before 4.9.2 has a buffer over-read in smbutil.c:name_len().

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12883

Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of service (application crash) via a crafted regular expression with an invalid '\N{U+...}' escape.

CVSS3: 9.1
6%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12877

Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12876

Heap-based buffer overflow in enhance.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.

CVSS3: 6.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12875

The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU consumption) via a crafted file.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12874

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12873

SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified other impacts by leveraging incorrect persistent NameID generation when an Identity Provider (IdP) is misconfigured.

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12872

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote attackers to conduct timing side-channel attacks by leveraging use of the standard comparison operator to compare secret material against user input.

CVSS3: 5.9
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12871

The aesEncrypt method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.x through 1.14.11 makes it easier for context-dependent attackers to bypass the encryption protection mechanism by leveraging use of the first 16 bytes of the secret key as the initialization vector (IV).

CVSS3: 5.9
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12870

SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers.

CVSS3: 5.9
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12869

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentication source defined in config/authsources.php via vectors related to improper validation of user input.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12868

The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypass authentication by leveraging missing character conversions before an XOR operation.

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12867

The SimpleSAML_Auth_TimeLimitedToken class in SimpleSAMLphp 1.14.14 and earlier allows attackers with access to a secret token to extend its validity period by manipulating the prepended time offset.

CVSS3: 5.9
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12865

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

CVSS3: 9.8
6%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12864

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-12863

In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_pitch. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
3%
Низкий
около 9 лет назад

Уязвимостей на страницу