|
248241
|
7.8 |
HIGH
Local
|
fedoraproject gnome
|
fedora gtk-vnc
|
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) …
|
CWE-118
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5884
|
2024-11-21 12:28 |
2017-03-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248242
|
9.8 |
CRITICAL
Network
|
rubyzip_project debian
|
rubyzip debian_linux
|
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "…
|
CWE-22
Path Traversal
|
CVE-2017-5946
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248243
|
3.7 |
LOW
Network
|
w3
|
high_resolution_time_api
|
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the http…
|
NVD-CWE-noinfo
|
CVE-2017-5928
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248244
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5927
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248245
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5926
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248246
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU o…
|
CWE-200
Information Exposure
|
CVE-2017-5925
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248247
|
7.8 |
HIGH
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and conseque…
|
NVD-CWE-noinfo
|
CVE-2017-5669
|
2024-11-21 12:28 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248248
|
9.8 |
CRITICAL
Network
|
metalgenix
|
genixcms
|
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
|
CWE-352
Origin Validation Error
|
CVE-2017-5959
|
2024-11-21 12:28 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248249
|
7.8 |
HIGH
Local
|
gomlab
|
gom_player
|
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5881
|
2024-11-21 12:28 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248250
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a…
|
CWE-362
Race Condition
|
CVE-2017-6001
|
2024-11-21 12:28 |
2017-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|