|
256081
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.
|
CWE-20
Improper Input Validation
|
CVE-2017-14489
|
2024-11-21 12:12 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256082
|
7.3 |
HIGH
Local
|
gentoo
|
sci-mathematics-gimps
|
The Gentoo sci-mathematics/gimps package before 28.10-r1 for Great Internet Mersenne Prime Search (GIMPS) allows local users to gain privileges by creating a hard link under /var/lib/gimps, because a…
|
CWE-269
Improper Privilege Management
|
CVE-2017-14484
|
2024-11-21 12:12 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256083
|
5.5 |
MEDIUM
Local
|
gentoo
|
dev-python-flower
|
flower.initd in the Gentoo dev-python/flower package before 0.9.1-r1 for Celery Flower sets PID file ownership to a non-root account, which might allow local users to kill arbitrary processes by leve…
|
CWE-362
Race Condition
|
CVE-2017-14483
|
2024-11-21 12:12 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256084
|
8.8 |
HIGH
Network
|
gnu debian
|
emacs debian_linux
|
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell…
|
NVD-CWE-noinfo
|
CVE-2017-14482
|
2024-11-21 12:12 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256085
|
5.5 |
MEDIUM
Local
|
xen
|
xen
|
Memory leak in Xen 3.3 through 4.8.x allows guest OS users to cause a denial of service (ARM or x86 AMD host OS memory consumption) by continually rebooting, because certain cleanup is skipped if no …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14431
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256086
|
7.5 |
HIGH
Network
|
dlink
|
dir-850l_firmware
|
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allow remote attackers to cause a denial of service (daemon crash) via craft…
|
CWE-20
Improper Input Validation
|
CVE-2017-14430
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256087
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-850l_firmware
|
The DHCP client on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices allows unauthenticated remote code execution as root beca…
|
CWE-78
OS Command
|
CVE-2017-14429
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256088
|
7.8 |
HIGH
Local
|
dlink
|
dir-850l_firmware
|
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/hostapd* permissions.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14428
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256089
|
7.8 |
HIGH
Local
|
dlink
|
dir-850l_firmware
|
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage_account_root permissions.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-14427
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256090
|
7.8 |
HIGH
Local
|
dlink
|
dir-850l_firmware
|
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0644 /var/etc/shadow (aka the /etc/shadow symlink target) permissions.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2017-14426
|
2024-11-21 12:12 |
2017-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|