|
255681
|
8.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
arch/x86/mm.c in Xen allows local PV guest OS users to gain host OS privileges via vectors related to map_grant_ref.
|
CWE-120
Classic Buffer Overflow
|
CVE-2017-12137
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255682
|
7.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
Race condition in the grant table code in Xen 4.6.x through 4.9.x allows local guest OS administrators to cause a denial of service (free list corruption and host crash) or gain privileges on the hos…
|
CWE-362
Race Condition
|
CVE-2017-12136
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255683
|
8.8 |
HIGH
Local
|
xen citrix debian
|
xen xenserver debian_linux
|
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
|
CWE-682
Incorrect Calculation
|
CVE-2017-12135
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255684
|
8.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cau…
|
CWE-682
Incorrect Calculation
|
CVE-2017-12134
|
2024-11-21 12:08 |
2017-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255685
|
8.8 |
HIGH
Network
|
supervisord fedoraproject debian redhat
|
supervisor fedora debian_linux cloudforms
|
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC req…
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-11610
|
2024-11-21 12:08 |
2017-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255686
|
7.8 |
HIGH
Local
|
razer
|
synapse
|
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan horse (1) RazerConfigNative.dll or (2) RazerConfigNati…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11653
|
2024-11-21 12:08 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255687
|
8.4 |
HIGH
Local
|
razer
|
synapse
|
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Trojan horse dbghelp.dll file.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-11652
|
2024-11-21 12:08 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255688
|
6.5 |
MEDIUM
Network
|
mindwerks
|
wildmidi
|
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11664
|
2024-11-21 12:08 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255689
|
6.5 |
MEDIUM
Network
|
mindwerks
|
wildmidi
|
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11663
|
2024-11-21 12:08 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255690
|
7.5 |
HIGH
Network
|
mindwerks
|
wildmidi
|
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted mid file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11662
|
2024-11-21 12:08 |
2017-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|