|
251431
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
|
CWE-416
Use After Free
|
CVE-2017-17814
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251432
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syn…
|
CWE-416
Use After Free
|
CVE-2017-17813
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251433
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17812
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251434
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-17811
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251435
|
5.5 |
MEDIUM
Local
|
nasm canonical
|
netwide_assembler ubuntu_linux
|
In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of…
|
CWE-20
Improper Input Validation
|
CVE-2017-17810
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251436
|
7.8 |
HIGH
Local
|
goldenfrog
|
vyprvpn
|
In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the argum…
|
CWE-426
Untrusted Search Path
|
CVE-2017-17809
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251437
|
3.3 |
LOW
Local
|
linux
|
linux_kernel
|
The KEYS subsystem in the Linux kernel before 4.14.6 omitted an access-control check when adding a key to the current task's "default request-key keyring" via the request_key() system call, allowing …
|
CWE-862
Missing Authorization
|
CVE-2017-17807
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251438
|
7.8 |
HIGH
Local
|
linux suse debian opensuse_project opensuse canonical
|
linux_kernel linux_enterprise_server linux_enterprise_desktop debian_linux leap linux_enterprise_server_for_raspberry_pi ubuntu_linux
|
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_A…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17806
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251439
|
7.8 |
HIGH
Local
|
linux suse debian opensuse_project opensuse canonical
|
linux_kernel linux_enterprise_server linux_enterprise_desktop debian_linux leap linux_enterprise_server_for_raspberry_pi ubuntu_linux
|
The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYP…
|
CWE-20
Improper Input Validation
|
CVE-2017-17805
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251440
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-sg108e_firmware
|
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-17747
|
2024-11-21 12:18 |
2017-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|