Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-1000456

больше 8 лет назад

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000450

больше 8 лет назад

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000445

больше 8 лет назад

ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000433

больше 8 лет назад

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1000427

больше 8 лет назад

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1000426

больше 8 лет назад

MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-1000422

больше 8 лет назад

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000421

больше 8 лет назад

Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000420

больше 8 лет назад

Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000419

больше 8 лет назад

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000418

больше 8 лет назад

The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000417

больше 8 лет назад

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2017-1000415

больше 8 лет назад

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-1000410

почти 9 лет назад

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these configuration messages, an attacker can also gain some control over which data will be held in the uninitialized stack variables. This can allow him to bypass KASLR, and stack canaries protection - as both pointers and stack canaries may be leaked in this manner. Combining this vulnerability (for example) with the previously disclosed RCE vulnerability in L2CAP configuration parsing (CVE-2017-1000251) may allow an attacker to exploit the RCE against kernels which were built with the above mitigations. These are the specifics of this vulnerability: In the function l2cap_parse_conf_rsp and in the function l2cap_parse_conf_req the...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-1000409

больше 8 лет назад

A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2017-1000408

больше 8 лет назад

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-1000407

почти 9 лет назад

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2017-1000405

почти 9 лет назад

The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2017-1000401

больше 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.

CVSS3: 2.2
EPSS: Низкий
ubuntu логотип

CVE-2017-1000400

больше 8 лет назад

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-1000456

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

CVSS3: 8.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000450

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Opencv 3.3 and earlier.

CVSS3: 8.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000445

ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service

CVSS3: 6.5
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000433

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.

CVSS3: 8.1
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000427

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

CVSS3: 6.1
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000426

MapProxy version 1.10.3 and older is vulnerable to a Cross Site Scripting attack in the demo service resulting in possible information disclosure.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000422

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution

CVSS3: 8.8
2%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000421

Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution

CVSS3: 9.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000420

Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000419

phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.

CVSS3: 7.5
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000418

The WildMidi_Open function in WildMIDI since commit d8a466829c67cacbb1700beded25c448d99514e5 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
3%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000417

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

CVSS3: 5.3
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000415

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.

CVSS3: 5.9
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000410

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned to an attacker in their uninitialized state. By manipulating the code flows that precede the handling of these configuration messages, an attacker can also gain some control over which data will be held in the uninitialized stack variables. This can allow him to bypass KASLR, and stack canaries protection - as both pointers and stack canaries may be leaked in this manner. Combining this vulnerability (for example) with the previously disclosed RCE vulnerability in L2CAP configuration parsing (CVE-2017-1000251) may allow an attacker to exploit the RCE against kernels which were built with the above mitigations. These are the specifics of this vulnerability: In the function l2cap_parse_conf_rsp and in the function l2cap_parse_conf_req the...

CVSS3: 7.5
4%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-1000409

A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000408

A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.

CVSS3: 7.8
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000407

The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.

CVSS3: 7.4
1%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-1000405

The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside the THP implementation. touch_pmd() can be reached by get_user_pages(). In such case, the pmd will become dirty. This scenario breaks the new can_follow_write_pmd()'s logic - pmd can become dirty without going through a COW cycle. This bug is not as severe as the original "Dirty cow" because an ext4 file (or any other regular file) cannot be mapped using THP. Nevertheless, it does allow us to overwrite read-only huge pages. For example, the zero huge page and sealed shmem files can be overwritten (since their mapping can be populated using THP). Note that after the first write page-fault to the zero page, it will be replaced with a new fresh (and zeroed) thp.

CVSS3: 7
3%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2017-1000401

The Jenkins 2.73.1 and earlier, 2.83 and earlier default form control for passwords and other secrets, <f:password/>, supports form validation (e.g. for API keys). The form validation AJAX requests were sent via GET, which could result in secrets being logged to a HTTP access log in non-default configurations of Jenkins, and made available to users with access to these log files. Form validation for <f:password/> is now always sent via POST, which is typically not logged.

CVSS3: 2.2
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2017-1000400

The Jenkins 2.73.1 and earlier, 2.83 and earlier remote API at /job/(job-name)/api contained information about upstream and downstream projects. This included information about tasks that the current user otherwise has no access to, e.g. due to lack of Item/Read permission. This has been fixed, and the API now only lists upstream and downstream projects that the current user has access to.

CVSS3: 4.3
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу