|
257401
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1 Gigabyte of memory is allocated (the maximum under the 1/4 restriction) then t…
|
NVD-CWE-noinfo
|
CVE-2017-1000371
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257402
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address…
|
NVD-CWE-noinfo
|
CVE-2017-1000370
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257403
|
4.0 |
MEDIUM
Local
|
exim debian
|
exim debian_linux
|
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2017-1000369
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257404
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment poin…
|
NVD-CWE-noinfo
|
CVE-2017-1000365
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257405
|
7.4 |
HIGH
Local
|
linux
|
linux_kernel
|
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this af…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000364
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257406
|
7.8 |
HIGH
Local
|
redhat suse novell openstack opensuse gnu debian mcafee
|
enterprise_linux_desktop enterprise_linux enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_eus enterprise_linux_server_tus enterprise_linux_server
|
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-1000366
|
2024-11-21 12:04 |
2017-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257407
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being able to read information belonging to other users, i…
|
CWE-200
Information Exposure
|
CVE-2017-1000380
|
2024-11-21 12:04 |
2017-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257408
|
8.2 |
HIGH
Local
|
sudo_project
|
sudo
|
Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function resulting in information disclosure and command executio…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000368
|
2024-11-21 12:04 |
2017-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257409
|
6.4 |
MEDIUM
Local
|
sudo_project
|
sudo
|
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
|
CWE-362
Race Condition
|
CVE-2017-1000367
|
2024-11-21 12:04 |
2017-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257410
|
7.5 |
HIGH
Network
|
opendaylight
|
opendaylight
|
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to th…
|
NVD-CWE-noinfo
|
CVE-2017-1000361
|
2024-11-21 12:04 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|