Search

Found 3,836 results in 1918ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-12868 critical 9.8 9.8 FIX debian debian simplesamlphpphp 9y ago The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attackers to conduct session fixation attacks or possibly bypas…
CVE-2015-7700 critical 9.8 9.8 FIX debian debian pngcrush_project 9y ago Double-free vulnerability in the sPLT chunk structure and png.c in pngcrush before 1.7.87 allows attackers to have unspecified impact via unknown vectors.
CVE-2017-14064 critical 9.8 9.8 slesdebian debian rhel ruby-lang 9y ago Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
CVE-2017-14062 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-14061 critical 9.8 9.8 FIX debian debian gnu 9y ago Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2013-7426 critical 9.8 9.8 FIX debian debian kamailio 9y ago Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
CVE-2017-12865 critical 9.8 9.8 FIX debian debian intel 9y ago Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string pass…
CVE-2017-13715 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto, ip_proto, and thoff are initialized, which allows remote attackers to cause a…
CVE-2017-0899 critical 9.8 9.8 FIX slesdebian debian rhel rubygems 9y ago RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape seque…
CVE-2017-8380 critical 9.8 9.8 FIX slesdebian debian qemu 9y ago Buffer overflow in the "megasas_mmio_write" function in Qemu 2.9.0 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2015-1430 critical 9.8 9.8 FIX debian debian xymon 9y ago Buffer overflow in xymon 4.3.17-1.
CVE-2014-9513 critical 9.8 9.8 debian debian debian 9y ago Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
CVE-2013-0870 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
CVE-2015-5224 critical 9.8 9.8 FIX slesdebian debian kernel 9y ago The mkostemp function in login-utils in util-linux when used incorrectly allows remote attackers to cause file name collision and possibly other attacks.
CVE-2017-12858 critical 9.8 9.8 FIX arch arch slesdebian debian libzip 9y ago Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.
CVE-2017-13139 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
CVE-2007-5199 critical 9.8 9.8 FIX debian debian x 9y ago A single byte overflow in catalogue.c in X.Org libXfont 1.3.1 allows remote attackers to have unspecified impact.
CVE-2015-1817 critical 9.8 9.8 FIX debian debian musl-libc 9y ago Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors.
CVE-2017-12942 critical 9.8 9.8 FIX slesdebian debian rarlab 9y ago libunrar.a in UnRAR before 5.5.7 has a buffer overflow in the Unpack::LongLZ function.
CVE-2017-12941 critical 9.8 9.8 FIX slesdebian debian rarlab 9y ago libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.
CVE-2017-12940 critical 9.8 9.8 FIX slesdebian debian rarlab 9y ago libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
CVE-2017-7555 critical 9.8 9.8 FIX debian debian sles augeas 9y ago Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could send crafted strings that would cause the applicatio…
CVE-2011-0469 critical 9.8 9.8 FIX debian debian 9y ago Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
CVE-2017-7551 critical 9.8 9.8 FIX debian debian fedoraproject 9y ago 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.
CVE-2017-7546 critical 9.8 9.8 FIX arch arch slesdebian debian postgresql 9y ago PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
CVE-2017-9800 critical 9.8 9.8 FIX arch arch slesdebian debian apache 9y ago A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run an arbitrary shell command. Such a URL could be ge…
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2017-12762 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux …
CVE-2015-6816 critical 9.8 9.8 FIX debian debianfedora fedora ganglia 9y ago ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
CVE-2015-2311 critical 9.8 9.8 FIX debian debian capnproto 9y ago Integer underflow in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 might allow remote peers to cause a denial of service or possibly obtain sensitive information from memory or execut…
CVE-2015-2310 critical 9.1 9.1 FIX debian debian capnproto 9y ago Integer overflow in layout.c++ in Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service or possibly obtain sensitive information from memory v…
CVE-2012-2781 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2780.
CVE-2012-2780 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2778, and CVE-2012-2781.
CVE-2012-2778 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2773, CVE-2012-2780, and CVE-2012-2781.
CVE-2012-2773 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2771, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.
CVE-2012-2771 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Unspecified vulnerability in FFmpeg before 0.10.3 has unknown impact and attack vectors, a different vulnerability than CVE-2012-2773, CVE-2012-2778, CVE-2012-2780, and CVE-2012-2781.
CVE-2010-3845 critical 9.8 9.8 FIX debian debian apache_authenhook_project 9y ago libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
CVE-2017-3653 low 3.1 3.1 slesdebian debian rhel oracleredhatmariadb 9y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Diffic…
CVE-2017-10193 low 3.1 3.1 FIX slesdebian debian rhel oraclenetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131.…
CVE-2017-10111 critical 9.6 9.6 FIX slesdebian debian rhel oraclenetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 8u131; Java SE Embedded: 8u131. Easily exploit…
CVE-2017-10110 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows unauthe…
CVE-2017-10107 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easi…
CVE-2017-10102 critical 9.0 9.0 FIX slesdebian debian rhel oraclephoenixcontactnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Diff…
CVE-2017-10101 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Eas…
CVE-2017-10096 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Eas…
CVE-2017-10090 critical 9.6 9.6 FIX slesdebian debian rhel oraclenetappredhat 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u141 and 8u131; Java SE Embedded: 8u131. Easil…
CVE-2017-10089 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Easily exploitable vulnerability allows una…
CVE-2017-10087 critical 9.6 9.6 FIX slesdebian debian rhel oracleredhatnetapp 9y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131…
CVE-2017-10086 critical 9.6 9.6 FIX slesdebian debian oraclenetapp 9y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthentic…
CVE-2015-7871 critical 9.8 10.0 EXPFIX debian debian ntpnetapp 9y ago Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.
CVE-2015-7853 critical 9.8 9.8 FIX debian debian ntpnetapp 9y ago The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative…
CVE-2015-7705 critical 9.8 9.8 FIX debian debian ntpnetappcitrix 9y ago The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests.
CVE-2017-12588 critical 9.8 9.8 FIX slesdebian debian rsyslog 9y ago The zmq3 input and output modules in rsyslog before 8.28.0 interpreted description fields as format strings, possibly allowing a format string attack with unspecified impact.
CVE-2017-12562 critical 9.8 9.8 FIX slesarch archdebian debian libsndfile_project 9y ago Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unsp…
CVE-2017-12424 critical 9.8 9.8 FIX slesdebian debian shadow_project 9y ago In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other me…
CVE-2017-11721 critical 9.8 9.8 FIX debian debian ioquake3 9y ago Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.
CVE-2017-12065 critical 9.8 9.8 FIX debian debian cacti 9y ago spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter.
CVE-2017-11720 critical 9.8 9.8 FIX arch archdebian debian lame_project 9y ago There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
CVE-2017-11643 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths.
CVE-2017-11641 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.
CVE-2017-11637 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
CVE-2017-11636 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
CVE-2017-11543 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 9y ago tcpdump 4.9.0 has a buffer overflow in the sliplink_print function in print-sl.c.
CVE-2017-11542 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 9y ago tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.
CVE-2017-11541 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 9y ago tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.
CVE-2017-7480 critical 9.8 9.8 FIX arch archdebian debian rootkit_hunter_project 9y ago rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.
CVE-2015-3886 critical 9.8 9.8 FIX debian debian libinfinity_project 9y ago libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
CVE-2017-10984 critical 9.8 9.8 FIX arch arch slesdebian debian freeradius 9y ago multiple issues in freeradius
CVE-2017-10979 critical 9.8 9.8 FIX arch archdebian debian freeradius 9y ago An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary c…
CVE-2017-1000056 critical 9.8 9.8 FIX debian debian kubernetes 9y ago Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
CVE-2017-1000047 critical 9.8 9.8 debian debian rbenv_project 9y ago rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution
CVE-2017-1000044 critical 9.8 9.8 FIX debian debian gnome 9y ago gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
CVE-2017-9788 critical 9.1 9.1 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi…
CVE-2017-11139 critical 9.8 9.8 FIX debian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
CVE-2017-11125 critical 9.8 9.8 FIX debian debian xar_project 9y ago libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.
CVE-2017-11124 critical 9.8 9.8 FIX debian debian xar_project 9y ago libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.
CVE-2017-1000082 critical 9.8 9.8 FIX slesdebian debian systemd_project 9y ago systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
CVE-2017-10966 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result …
CVE-2017-10965 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
CVE-2017-10989 critical 9.8 9.8 FIX slesdebian debian sqlite 9y ago The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer ove…
CVE-2016-4000 critical 9.8 9.8 FIX debian debian jython_project 9y ago Deserialization of Untrusted Data in Jython
CVE-2017-10921 critical 10.0 10.0 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (coun…
CVE-2017-10920 critical 10.0 10.0 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a deni…
CVE-2017-10918 critical 10.0 10.0 FIX slesdebian debian 9y ago Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
CVE-2017-10917 critical 9.1 9.1 FIX slesdebian debian 9y ago Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly o…
CVE-2017-10915 critical 9.0 9.0 FIX slesdebian debian 9y ago The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
CVE-2017-10913 critical 9.8 9.8 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain priv…
CVE-2017-10912 critical 10.0 10.0 FIX slesdebian debian 9y ago Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.
CVE-2017-10804 critical 9.8 9.8 FIX debian debian odoo 9y ago In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 c…
CVE-2017-10807 critical 9.8 9.8 FIX slesdebian debian jabberd2 9y ago JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
CVE-2017-10788 critical 9.8 9.8 FIX slesdebian debian dbd-mysql_project 9y ago The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) ce…
CVE-2017-2292 critical 9.0 9.0 FIX debian debian puppet 9y ago Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.sa…
CVE-2017-10699 critical 9.8 9.8 FIX arch archdebian debian videolan 9y ago arbitrary code execution in vlc
CVE-2017-10685 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2017-10684 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2017-10672 critical 9.8 9.8 FIX slesarch archdebian debian xml-libxml_project 9y ago Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
CVE-2017-9772 critical 9.8 9.8 FIX debian debian ocaml 9y ago Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_N…
CVE-2012-6706 critical 9.8 9.8 FIX slesarch archdebian debian sophosrarlab 9y ago A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. …
CVE-2017-7679 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
CVE-2017-3169 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.