Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-10966

около 9 лет назад

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10965

около 9 лет назад

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10929

около 9 лет назад

The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10928

около 9 лет назад

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10923

около 9 лет назад

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10922

около 9 лет назад

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10921

около 9 лет назад

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2017-10920

около 9 лет назад

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2017-10919

около 9 лет назад

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10918

около 9 лет назад

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2017-10917

около 9 лет назад

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2017-10916

около 9 лет назад

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10915

около 9 лет назад

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
EPSS: Низкий
ubuntu логотип

CVE-2017-10914

около 9 лет назад

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-10913

около 9 лет назад

The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10912

около 9 лет назад

Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2017-10911

около 9 лет назад

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10908

почти 9 лет назад

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10905

почти 9 лет назад

A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-10904

почти 9 лет назад

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-10966

An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result in use-after-free conditions on each access of the hash table.

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10965

An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10929

The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function in kern/disk.c in GNU GRUB 2.02.

CVSS3: 7.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10928

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information from process memory or possibly have unspecified other impact via a crafted SVG document that is mishandled in the GetUserSpaceCoordinateValue function in coders/svg.c.

CVSS3: 8.8
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10923

Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-225.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10922

The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cause a denial of service (loss of grant trackability), aka XSA-224 bug 3.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10921

The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 2.

CVSS3: 10
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10920

The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privileged host OS access, aka XSA-224 bug 1.

CVSS3: 10
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10919

Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hypervisor crash), aka XSA-223.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10918

Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.

CVSS3: 10
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10917

Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly obtain sensitive information, aka XSA-221.

CVSS3: 9.1
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10916

The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU) features, which makes it easier for guest OS users to defeat ASLR and other protection mechanisms, aka XSA-220.

CVSS3: 7.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10915

The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.

CVSS3: 9
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10914

The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA-218 bug 2.

CVSS3: 8.1
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10913

The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10912

Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.

CVSS3: 10
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10911

The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive information from host OS (or other guest OS) kernel memory by leveraging the copying of uninitialized padding fields in Xen block-interface response structures, aka XSA-216.

CVSS3: 6.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10908

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/2 header.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10905

A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

CVSS3: 5.3
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10904

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS3: 9.8
2%
Низкий
почти 9 лет назад

Уязвимостей на страницу