|
255341
|
9.8 |
CRITICAL
Network
|
apache
|
ambari
|
During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.
|
CWE-276
Incorrect Default Permissions
|
CVE-2017-5642
|
2024-11-21 12:28 |
2017-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255342
|
5.5 |
MEDIUM
Local
|
artifex
|
ghostscript
|
The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) …
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-5951
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255343
|
5.5 |
MEDIUM
Local
|
yaml-cpp_project
|
yaml-cpp
|
The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5950
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255344
|
9.8 |
CRITICAL
Network
|
apple
|
safari
|
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possib…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5949
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255345
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.
|
CWE-416
Use After Free
|
CVE-2017-5924
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255346
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse fu…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5923
|
2024-11-21 12:28 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255347
|
5.4 |
MEDIUM
Network
|
netcomm
|
nb16wv-02_firmware
|
Cross-site scripting (XSS) vulnerability in the NetComm NB16WV-02 router with firmware NB16WV_R0.09 allows remote authenticated users to inject arbitrary web script or HTML via the S801F0334 paramete…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5900
|
2024-11-21 12:28 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255348
|
8.8 |
HIGH
Local
|
honeywell
|
intermec_pc23_firmware intermec_pc42_firmware intermec_pc43_firmware intermec_pd43_firmware intermec_pm23_firmware intermec_pm42_firmware intermec_pm43_firmware
|
Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin/lua installed setuid to the itadmin account, whic…
|
CWE-269
Improper Privilege Management
|
CVE-2017-5671
|
2024-11-21 12:28 |
2017-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255349
|
5.5 |
MEDIUM
Local
|
qemu debian redhat
|
qemu debian_linux openstack virtualization
|
The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and QEMU process crash) via vectors r…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-5973
|
2024-11-21 12:28 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255350
|
7.8 |
HIGH
Local
|
gnu
|
bash
|
The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.
|
CWE-20
Improper Input Validation
|
CVE-2017-5932
|
2024-11-21 12:28 |
2017-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|