|
198191
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a…
|
CWE-665
Improper Initialization
|
CVE-2017-13715
|
2024-11-21 12:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198192
|
5.5 |
MEDIUM
Local
|
gnu
|
binutils
|
The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application cr…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-13716
|
2024-11-21 12:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198193
|
7.5 |
HIGH
Network
|
lame_project
|
lame
|
NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argument.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13712
|
2024-11-21 12:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198194
|
7.5 |
HIGH
Network
|
gnu
|
binutils
|
The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer der…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13710
|
2024-11-21 12:11 |
2017-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198195
|
7.5 |
HIGH
Network
|
flightgear
|
flightgear
|
In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the contents of the global Property Tree.
|
CWE-20
Improper Input Validation
|
CVE-2017-13709
|
2024-11-21 12:11 |
2017-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198196
|
9.8 |
CRITICAL
Network
|
axcient
|
replibit
|
Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. The vi program can be accessed through sudo, in or…
|
CWE-269
Improper Privilege Management
|
CVE-2017-13707
|
2024-11-21 12:11 |
2017-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198197
|
6.1 |
MEDIUM
Network
|
finecms_project
|
finecms
|
controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.
|
CWE-79
Cross-site Scripting
|
CVE-2017-13697
|
2024-11-21 12:11 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198198
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain …
|
CWE-200
Information Exposure
|
CVE-2017-13695
|
2024-11-21 12:11 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198199
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext caches and causes a kernel stack dump, which allows …
|
CWE-200
Information Exposure
|
CVE-2017-13694
|
2024-11-21 12:11 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198200
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to…
|
CWE-200
Information Exposure
|
CVE-2017-13693
|
2024-11-21 12:11 |
2017-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|