Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-10873

почти 9 лет назад

OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-10872

почти 9 лет назад

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10869

почти 9 лет назад

Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10868

почти 9 лет назад

H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10810

около 9 лет назад

Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10807

около 9 лет назад

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10806

около 9 лет назад

Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10800

около 9 лет назад

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10799

около 9 лет назад

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10794

около 9 лет назад

When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10792

около 9 лет назад

There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10791

около 9 лет назад

There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10790

около 9 лет назад

The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10789

около 9 лет назад

The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-10788

около 9 лет назад

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10784

около 9 лет назад

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2017-10708

около 9 лет назад

An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10699

около 9 лет назад

avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-10690

больше 8 лет назад

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-10689

больше 8 лет назад

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-10873

OpenAM (Open Source Edition) allows an attacker to bypass authentication and access unauthorized contents via unspecified vectors. Note that this vulnerability affects OpenAM (Open Source Edition) implementations configured as SAML 2.0IdP, and switches authentication methods based on AuthnContext requests sent from the service provider.

CVSS3: 8.1
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10872

H2O version 2.2.3 and earlier allows remote attackers to cause a denial of service in the server via unspecified vectors.

CVSS3: 6.5
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10869

Buffer overflow in H2O version 2.2.2 and earlier allows remote attackers to cause a denial-of-service in the server via unspecified vectors.

CVSS3: 7.5
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10868

H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted HTTP/1 header.

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-10810

Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

CVSS3: 7.5
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10807

JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.

CVSS3: 9.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10806

Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.

CVSS3: 5.5
0%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10800

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.

CVSS3: 5.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10799

When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().

CVSS3: 5.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10794

When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.

CVSS3: 5.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10792

There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10791

There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SPSS data into CSV format. A crafted input will lead to a remote denial of service attack.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10790

The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node structure. It may lead to a remote denial of service attack.

CVSS3: 7.5
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10789

The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this setting's documentation has a "your communication with the server will be encrypted" statement), which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack, a related issue to CVE-2015-3152.

CVSS3: 5.9
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10788

The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) certain error responses from a MySQL server or (2) a loss of a network connection to a MySQL server. The use-after-free defect was introduced by relying on incorrect Oracle mysql_stmt_close documentation and code examples.

CVSS3: 9.8
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10784

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

CVSS3: 8.8
16%
Средний
около 9 лет назад
ubuntu логотип
CVE-2017-10708

An issue was discovered in Apport through 2.20.x. In apport/report.py, Apport sets the ExecutablePath field and it then uses the path to run package specific hooks without protecting against path traversal. This allows remote attackers to execute arbitrary code via a crafted .crash file.

CVSS3: 7.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10699

avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write due to calling memcpy() with a wrong size, leading to a denial of service (application crash) or possibly code execution.

CVSS3: 9.8
4%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-10690

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from. This was resolved in Puppet Agent 5.3.4, included in Puppet Enterprise 2017.3.4

CVSS3: 6.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-10689

In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5.3.4 and 1.10.10 included a fix to this vulnerability.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад

Уязвимостей на страницу