|
248811
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5927
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248812
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU ope…
|
CWE-200
Information Exposure
|
CVE-2017-5926
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248813
|
7.5 |
HIGH
Network
|
intel amd samsung nvidia allwinner
|
core_i7-2620qm core_i7-6700k core_i5_m480 fx-8120_8-core e-350 atom_c2750 athlon_ii_640_x4 exynos_5800 celeron_n2840 fx-8320_8-core xeon_e5-2658_v2 tegra_k1_cd580m-a1…
|
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU o…
|
CWE-200
Information Exposure
|
CVE-2017-5925
|
2024-11-21 12:28 |
2017-02-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248814
|
7.8 |
HIGH
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and conseque…
|
NVD-CWE-noinfo
|
CVE-2017-5669
|
2024-11-21 12:28 |
2017-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248815
|
9.8 |
CRITICAL
Network
|
metalgenix
|
genixcms
|
CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.
|
CWE-352
Origin Validation Error
|
CVE-2017-5959
|
2024-11-21 12:28 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248816
|
7.8 |
HIGH
Local
|
gomlab
|
gom_player
|
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5881
|
2024-11-21 12:28 |
2017-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248817
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a…
|
CWE-362
Race Condition
|
CVE-2017-6001
|
2024-11-21 12:28 |
2017-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248818
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithr…
|
CWE-362 CWE-617
Race Condition Reachable Assertion
|
CVE-2017-5986
|
2024-11-21 12:28 |
2017-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248819
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-6014
|
2024-11-21 12:28 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248820
|
5.4 |
MEDIUM
Network
|
intersect_alliance
|
snare_epilog
|
Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5998
|
2024-11-21 12:28 |
2017-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|