|
249821
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17811
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249822
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of…
|
CWE-20
Improper Input Validation
|
CVE-2017-17810
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249823
|
7.8 |
HIGH
Local
|
goldenfrog
|
vyprvpn
|
In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the argum…
|
CWE-426
Untrusted Search Path
|
CVE-2017-17809
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249824
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing …
|
CWE-862
Missing Authorization
|
CVE-2017-17807
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249825
|
7.8 |
HIGH
Local
|
linux suse debian opensuse_project opensuse canonical
|
linux_kernel linux_enterprise_server linux_enterprise_desktop debian_linux leap linux_enterprise_server_for_raspberry_pi ubuntu_linux
|
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_A…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17806
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249826
|
7.8 |
HIGH
Local
|
linux suse debian opensuse_project opensuse canonical
|
linux_kernel linux_enterprise_server linux_enterprise_desktop debian_linux leap linux_enterprise_server_for_raspberry_pi ubuntu_linux
|
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYP…
|
CWE-20
Improper Input Validation
|
CVE-2017-17805
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249827
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-sg108e_firmware
|
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-17747
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249828
|
6.8 |
MEDIUM
Adjacent
|
tp-link
|
tl-sg108e_firmware
|
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authenticati…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-17746
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249829
|
5.4 |
MEDIUM
Network
|
tp-link
|
tl-sg108e_firmware
|
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17745
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249830
|
8.8 |
HIGH
Network
|
otrs debian
|
otrs debian_linux
|
Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might allow remote attackers to hijack web sessions and consequent…
|
CWE-200
Information Exposure
|
CVE-2017-17476
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|