|
247001
|
9.8 |
CRITICAL
Network
|
oniguruma_project php
|
oniguruma php
|
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular ex…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-9228
|
2024-11-21 12:35 |
2017-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247002
|
9.8 |
CRITICAL
Network
|
oniguruma_project php
|
oniguruma php
|
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write or read occurs in next_state_val() during regu…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-9226
|
2024-11-21 12:35 |
2017-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247003
|
9.8 |
CRITICAL
Network
|
oniguruma_project ruby-lang php
|
oniguruma ruby php
|
An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-9225
|
2024-11-21 12:35 |
2017-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247004
|
7.5 |
HIGH
Network
|
systemd_project
|
systemd
|
systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9217
|
2024-11-21 12:35 |
2017-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247005
|
6.5 |
MEDIUM
Network
|
artifex debian
|
jbig2dec debian_linux
|
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will c…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9216
|
2024-11-21 12:35 |
2017-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247006
|
9.8 |
CRITICAL
Network
|
openvswitch debian redhat
|
openvswitch debian_linux openstack virtualization_manager virtualization
|
In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pu…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2017-9214
|
2024-11-21 12:35 |
2017-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247007
|
7.5 |
HIGH
Network
|
bavarian_motor_works
|
bluetooth_stack
|
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2017-9212
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247008
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of se…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-9211
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247009
|
5.5 |
MEDIUM
Local
|
qpdf_project canonical
|
qpdf ubuntu_linux
|
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-9210
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247010
|
5.5 |
MEDIUM
Local
|
qpdf_project canonical
|
qpdf ubuntu_linux
|
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpd…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-9209
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|