|
251461
|
7.5 |
HIGH
Network
|
miekg-dns_prject
|
miekg-dns
|
A denial of service flaw was found in miekg-dns before 1.0.4. A remote attacker could use carefully timed TCP packets to block the DNS server from accepting new connections.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-15133
|
2024-11-21 12:14 |
2018-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251462
|
7.5 |
HIGH
Network
|
dovecot debian canonical
|
dovecot debian_linux ubuntu_linux
|
A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performa…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15132
|
2024-11-21 12:14 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251463
|
8.8 |
HIGH
Network
|
fedoraproject mariadb percona
|
fedora mariadb xtradb_cluster
|
sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with S…
|
NVD-CWE-noinfo
|
CVE-2017-15365
|
2024-11-21 12:14 |
2018-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251464
|
4.3 |
MEDIUM
Network
|
emc
|
rsa_authentication_manager
|
The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerab…
|
CWE-89
SQL Injection
|
CVE-2017-15546
|
2024-11-21 12:14 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251465
|
8.1 |
HIGH
Network
|
fedoraproject
|
389_directory_server
|
It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticate…
|
-
|
CVE-2017-15135
|
2024-11-21 12:14 |
2018-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251466
|
9.8 |
CRITICAL
Network
|
symantec
|
reporter
|
Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts for management interface users. A remote attacker can use brute force search to …
|
CWE-287
Improper Authentication
|
CVE-2017-15531
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251467
|
7.5 |
HIGH
Network
|
thekelleys
|
dnsmasq
|
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostname…
|
NVD-CWE-noinfo
|
CVE-2017-15107
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251468
|
5.3 |
MEDIUM
Network
|
nlnetlabs debian canonical
|
unbound debian_linux ubuntu_linux
|
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) o…
|
CWE-20
Improper Input Validation
|
CVE-2017-15105
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251469
|
5.9 |
MEDIUM
Network
|
powerdns
|
recursor
|
An issue has been found in the DNSSEC parsing code of PowerDNS Recursor from 4.0.0 up to and including 4.0.6 leading to a memory leak when parsing specially crafted DNSSEC ECDSA keys. These keys are …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-15094
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251470
|
6.1 |
MEDIUM
Network
|
powerdns
|
recursor
|
A cross-site scripting issue has been found in the web interface of PowerDNS Recursor from 4.0.0 up to and including 4.0.6, where the qname of DNS queries was displayed without any escaping, allowing…
|
CWE-79
Cross-site Scripting
|
CVE-2017-15092
|
2024-11-21 12:14 |
2018-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|