Search

Found 3,838 results in 478ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-7239 critical 9.8 9.8 FIX debian debian ninka_project 9y ago Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
CVE-2017-7614 critical 9.8 9.8 FIX debian debian sles gnu 9y ago elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote a…
CVE-2017-0561 critical 9.8 10.0 EXPFIX debian debian linux-kernel 9y ago A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due …
CVE-2016-6809 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
CVE-2016-10229 critical 9.8 9.8 FIX slesarch archdebian debian 9y ago udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with …
CVE-2017-7407 low 2.4 2.4 FIX slesdebian debian haxx 9y ago The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a w…
CVE-2014-5009 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
CVE-2014-5008 critical 9.8 9.8 FIX debian debian snoopyredhat 9y ago Snoopy allows remote attackers to execute arbitrary commands.
CVE-2008-7313 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
CVE-2014-9826 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
CVE-2017-5226 critical 10.0 10.0 FIX debian debian sles rhel projectatomic 9y ago RHSA-2019:1143: flatpak security update (Important)
CVE-2014-6440 critical 9.8 9.8 FIX debian debian videolan 9y ago VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.
CVE-2016-10152 critical 9.8 9.8 FIX debian debian hesiod_project 9y ago The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root …
CVE-2016-9121 critical 9.1 9.1 FIX debian debian go-jose_project 9y ago go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received pu…
CVE-2017-7191 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
CVE-2017-6542 critical 9.8 10.0 EXPFIX suse susedebian debian putty 9y ago The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect…
CVE-2017-5511 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
CVE-2017-5337 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
CVE-2017-5336 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted Op…
CVE-2017-5334 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language in…
CVE-2016-10145 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
CVE-2016-10144 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
CVE-2016-10133 critical 9.8 9.8 FIX debian debian artifex 9y ago Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments …
CVE-2016-10128 critical 9.8 9.8 FIX slesarch archdebian debian libgit2_project 9y ago Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspec…
CVE-2015-8556 critical 10.0 10.0 EXPFIX slesdebian debian qemu 9y ago Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CVE-2015-8626 critical 9.8 9.8 FIX debian debian mediawiki 9y ago The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which ma…
CVE-2015-0855 critical 9.8 9.8 FIX debian debian pitivi 9y ago The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.
CVE-2017-5897 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu 9y ago The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds …
CVE-2017-5206 critical 9.0 9.0 FIX arch archdebian debian linux-kernel firejail_project 9y ago Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
CVE-2017-7226 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses…
CVE-2017-7214 critical 9.8 9.8 FIX slesdebian debian openstack 9y ago An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level lo…
CVE-2014-9939 critical 9.8 9.8 FIX debian debian gnu 9y ago ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
CVE-2017-5930 low 2.7 3.7 EXPFIX suse susedebian debian postfixadmin_project 9y ago The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission ch…
CVE-2015-8954 critical 9.8 9.8 FIX debian debian openinfosecfoundation 9y ago The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafte…
CVE-2014-9847 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu opensuse_projectimagemagick 9y ago The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
CVE-2014-9846 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
CVE-2014-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2014-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
CVE-2016-10253 critical 9.8 9.8 FIX slesdebian debian erlang 9y ago An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly speci…
CVE-2014-9852 critical 9.8 9.8 FIX slesdebian debiansuse suse imagemagick 9y ago distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
CVE-2017-6969 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak a…
CVE-2015-8981 critical 9.8 9.8 FIX slesdebian debian podofo_project 9y ago Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.
CVE-2016-5239 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
CVE-2017-5522 critical 9.8 9.8 FIX debian debian osgeo 9y ago Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary…
CVE-2016-10195 critical 9.8 9.8 FIX slesdebian debian libevent_project 9y ago The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack…
CVE-2016-10166 critical 9.8 9.8 FIX slesdebian debian libgd 9y ago Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors relate…
CVE-2017-5985 low 3.3 3.3 FIX arch archdebian debian linuxcontainers 9y ago lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ow…
CVE-2017-5668 critical 9.8 9.8 FIX debian debian bitlbee 9y ago bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact …
CVE-2016-10188 critical 9.8 9.8 FIX debian debian bitlbee 9y ago Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to exp…
CVE-2017-5929 critical 9.8 9.8 FIX debian debian qosredhat 9y ago QOS.ch Logback vulnerable to Deserialization of Untrusted Data
CVE-2016-4658 critical 9.8 9.8 FIX slesarch archdebian debian xmlsoft 9y ago xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, wh…
CVE-2016-8863 critical 9.8 9.8 debian debian libupnp_project 9y ago Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possi…
CVE-2016-7407 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
CVE-2016-7406 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
CVE-2016-10204 critical 9.8 9.8 FIX debian debian zoneminder 9y ago SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2016-10127 critical 9.0 9.0 slesdebian debian pysaml2_project 9y ago PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVE-2015-2877 low 3.3 3.3 debian debian linux-kernel rhel 9y ago Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other …
CVE-2017-5885 critical 9.8 9.8 FIX slesdebian debianfedora fedora gnome 9y ago Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly e…
CVE-2017-5581 critical 9.8 9.8 FIX slesdebian debian tigervnc 9y ago Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer bound…
CVE-2016-9558 critical 9.8 9.8 FIX arch archdebian debian libdwarf_project 9y ago (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negati…
CVE-2016-7553 low 3.3 3.3 FIX debian debian irssi 9y ago The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from …
CVE-2017-6350 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file,…
CVE-2017-6349 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, whic…
CVE-2017-5946 critical 9.8 9.8 FIX debian debian rubyzip_project 9y ago The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "…
CVE-2016-1245 critical 9.8 9.8 slesdebian debian quagga 9y ago It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSI…
CVE-2016-9400 critical 9.8 9.8 FIX fedora fedoradebian debian teeworlds 9y ago The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code…
CVE-2016-9814 critical 9.1 9.1 FIX debian debian simplesamlphp 9y ago The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers …
CVE-2016-10134 critical 9.8 10.0 EXPFIX debian debian zabbix 9y ago SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVE-2016-8859 critical 9.8 9.8 FIX debian debian etalabs 9y ago Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
CVE-2016-2788 critical 9.8 9.8 FIX debian debian puppet 9y ago MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
CVE-2015-8771 critical 9.8 9.8 FIX debian debian gosa_project 9y ago The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
CVE-2017-5953 critical 9.8 9.8 FIX arch arch slesdebian debian vim 9y ago vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer over…
CVE-2016-2148 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu busybox 9y ago Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-10192 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failur…
CVE-2016-10191 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by levera…
CVE-2016-10190 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a nega…
CVE-2016-2403 critical 9.8 9.8 FIX debian debian sensiolabs 10y ago Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CVE-2016-6199 critical 9.8 9.8 FIX debian debian gradle 10y ago ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
CVE-2016-6175 critical 9.8 10.0 EXPFIX debian debian php-gettext_project 10y ago Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
CVE-2015-8608 critical 9.8 9.8 FIX debian debian perl 10y ago The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive lette…
CVE-2016-7447 critical 9.8 9.8 FIX slesdebian debiansuse suse graphicsmagick 10y ago Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2016-7446 critical 9.8 9.8 FIX slesdebian debiansuse suse graphicsmagick 10y ago Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete…
CVE-2016-10150 critical 9.8 9.8 FIX slesdebian debian linux-kernel 10y ago Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or poss…
CVE-2016-9085 low 3.3 3.3 FIX debian debianfedora fedora webmproject 10y ago Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
CVE-2016-10164 critical 9.8 9.8 FIX slesdebian debian x.org 10y ago Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or e…
CVE-2017-5611 critical 9.8 9.8 FIX debian debian wordpressoracle 10y ago SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected…
CVE-2017-5486 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
CVE-2017-5485 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap().
CVE-2017-5484 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().
CVE-2017-5483 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse().
CVE-2017-5482 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.
CVE-2017-5342 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().
CVE-2017-5341 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().
CVE-2017-5205 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
CVE-2017-5204 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
CVE-2017-5203 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
CVE-2017-5202 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
CVE-2016-8575 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482.
CVE-2016-8574 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print().
CVE-2016-7993 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM).