|
198151
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-msdp.c by adding length validation.
|
CWE-20 CWE-835
Improper Input Validation Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-13767
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198152
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.4.0 and 2.2.0 to 2.2.8, the Profinet I/O dissector could crash with an out-of-bounds write. This was addressed in plugins/profinet/packet-dcerpc-pn-io.c by adding string validation.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-13766
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198153
|
7.5 |
HIGH
Network
|
wireshark debian
|
wireshark debian_linux
|
In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validat…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-13765
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198154
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13764
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198155
|
7.5 |
HIGH
Network
|
onosproject
|
onos
|
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-13763
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198156
|
6.1 |
MEDIUM
Network
|
onosproject
|
onos
|
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-13762
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198157
|
5.5 |
MEDIUM
Local
|
sleuthkit debian
|
the_sleuth_kit debian_linux
|
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13760
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198158
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the TracePoint() function in MagickCore/draw.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13758
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198159
|
5.5 |
MEDIUM
Local
|
gnu
|
binutils
|
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-ba…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-13757
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198160
|
5.5 |
MEDIUM
Local
|
sleuthkit debian
|
the_sleuth_kit debian_linux
|
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-13756
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|