Search

Found 17,057 results in 1881ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-11541 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 9y ago tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.
CVE-2017-7480 critical 9.8 9.8 FIX arch archdebian debian rootkit_hunter_project 9y ago rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.
CVE-2015-3886 critical 9.8 9.8 FIX debian debian libinfinity_project 9y ago libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.
CVE-2017-10984 critical 9.8 9.8 FIX arch arch slesdebian debian freeradius 9y ago multiple issues in freeradius
CVE-2017-10979 critical 9.8 9.8 FIX arch archdebian debian freeradius 9y ago An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary c…
CVE-2017-1000056 critical 9.8 9.8 FIX debian debian kubernetes 9y ago Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object.
CVE-2017-1000047 critical 9.8 9.8 debian debian rbenv_project 9y ago rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution
CVE-2017-1000044 critical 9.8 9.8 FIX debian debian gnome 9y ago gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering
CVE-2017-9788 critical 9.1 9.1 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi…
CVE-2017-11139 critical 9.8 9.8 FIX debian debian graphicsmagick 9y ago GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
CVE-2017-11125 critical 9.8 9.8 FIX debian debian xar_project 9y ago libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_get_path function in util.c.
CVE-2017-11124 critical 9.8 9.8 FIX debian debian xar_project 9y ago libxar.so in xar 1.6.1 has a NULL pointer dereference in the xar_unserialize function in archive.c.
CVE-2017-1000082 critical 9.8 9.8 FIX slesdebian debian systemd_project 9y ago systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.
CVE-2017-10966 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago An issue was discovered in Irssi before 1.0.4. While updating the internal nick list, Irssi could incorrectly use the GHashTable interface and free the nick while updating it. This would then result …
CVE-2017-10965 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago An issue was discovered in Irssi before 1.0.4. When receiving messages with invalid time stamps, Irssi would try to dereference a NULL pointer.
CVE-2017-10989 critical 9.8 9.8 FIX slesdebian debian sqlite 9y ago The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a crafted database, leading to a heap-based buffer ove…
CVE-2016-4000 critical 9.8 9.8 FIX debian debian jython_project 9y ago Deserialization of Untrusted Data in Jython
CVE-2017-10921 critical 10.0 10.0 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (coun…
CVE-2017-10920 critical 10.0 10.0 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a deni…
CVE-2017-10918 critical 10.0 10.0 FIX slesdebian debian 9y ago Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obtain privileged host OS access, aka XSA-222.
CVE-2017-10917 critical 9.1 9.1 FIX slesdebian debian 9y ago Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly o…
CVE-2017-10915 critical 9.0 9.0 FIX slesdebian debian 9y ago The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219.
CVE-2017-10913 critical 9.8 9.8 FIX slesdebian debian 9y ago The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain priv…
CVE-2017-10912 critical 10.0 10.0 FIX slesdebian debian 9y ago Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217.
CVE-2017-10804 critical 9.8 9.8 FIX debian debian odoo 9y ago In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 c…
CVE-2017-10807 critical 9.8 9.8 FIX slesdebian debian jabberd2 9y ago JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous c2s.xml option is not enabled.
CVE-2017-10788 critical 9.8 9.8 FIX slesdebian debian dbd-mysql_project 9y ago The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact by triggering (1) ce…
CVE-2017-2292 critical 9.0 9.0 FIX debian debian puppet 9y ago Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.sa…
CVE-2017-10699 critical 9.8 9.8 FIX arch archdebian debian videolan 9y ago arbitrary code execution in vlc
CVE-2017-10685 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2017-10684 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2017-10672 critical 9.8 9.8 FIX slesarch archdebian debian xml-libxml_project 9y ago Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.
CVE-2017-9772 critical 9.8 9.8 FIX debian debian ocaml 9y ago Insufficient sanitisation in the OCaml compiler versions 4.04.0 and 4.04.1 allows external code to be executed with raised privilege in binaries marked as setuid, by setting the CAML_CPLUGINS, CAML_N…
CVE-2012-6706 critical 9.8 9.8 FIX slesarch archdebian debian sophosrarlab 9y ago A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. …
CVE-2017-7679 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when sending a malicious Content-Type response header.
CVE-2017-3169 critical 9.8 9.8 FIX debian debianarch arch sles apache 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party modules call ap_hook_process_connection() during an HTTP request to an HTTPS port.
CVE-2017-3167 critical 9.8 9.8 FIX debian debianarch arch sles apachenetappredhat 9y ago In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being…
CVE-2017-9736 critical 9.8 9.8 FIX debian debian spip 9y ago SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a remote attacker to cause remote code execution.
CVE-2017-9728 critical 9.8 9.8 debian debian uclibc 9y ago In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression.
CVE-2017-2810 critical 9.8 9.8 FIX slesdebian debian python 9y ago An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can execute arbitrary python commands resulting in command execution. An attacker ca…
CVE-2014-9984 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon cras…
CVE-2016-7835 critical 9.1 9.1 FIX debian debian denah2o_project 9y ago Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.
CVE-2016-7050 critical 9.8 9.8 FIX rheldebian debian 9y ago SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remot…
CVE-2016-5405 critical 9.8 9.8 FIX debian debian sles rhel 9y ago 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstat…
CVE-2016-9961 critical 9.8 9.8 FIX slesdebian debianfedora fedora game-music-emu_projectnovell 9y ago game-music-emu before 0.6.1 mishandles unspecified integer values.
CVE-2017-9430 critical 9.8 10.0 EXP debian debian dnstracer_project 9y ago Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name ar…
CVE-2017-9433 critical 9.8 9.8 FIX slesdebian debian libmwaw_project 9y ago Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1P…
CVE-2017-9432 critical 9.8 9.8 FIX debian debian libstaroffice_project 9y ago Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx.
CVE-2017-9431 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-04-05 has an out-of-bounds write caused by a heap-based buffer overflow related to core/lib/iomgr/error.c.
CVE-2017-9417 critical 9.8 10.0 EXPFIX debian debian 9y ago Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.
CVE-2017-9148 critical 9.8 9.8 FIX arch arch slesdebian debian freeradius 9y ago authentication bypass in freeradius
CVE-2017-9265 critical 9.8 9.8 FIX slesdebian debian openvswitch 9y ago In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` in the function `ofputil_pull_ofp15_group_mod`.
CVE-2017-9264 critical 9.8 9.8 FIX debian debian openvswitch 9y ago In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6 packets in the functions `extract_l3_ipv6`, `extr…
CVE-2015-9059 critical 9.8 9.8 FIX debian debian picocom_project 9y ago picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line is executed by /bin/sh unsafely.
CVE-2016-10375 critical 9.8 9.8 FIX slesdebian debian yodl_project 9y ago Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.
CVE-2015-5211 critical 9.6 9.6 FIX debian debian vmware 9y ago Files or Directories Accessible to External Parties in org.springframework:spring-core
CVE-2017-9228 critical 9.8 9.8 FIX slesdebian debian oniguruma_projectphp 9y ago An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write occurs in bitset_set_range() during regular ex…
CVE-2017-9227 critical 9.8 9.8 FIX slesdebian debian oniguruma_projectphp 9y ago An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in mbc_enc_len() during regular express…
CVE-2017-9226 critical 9.8 9.8 FIX slesdebian debian oniguruma_projectphp 9y ago An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A heap out-of-bounds write or read occurs in next_state_val() during regu…
CVE-2017-9225 critical 9.8 9.8 FIX slesdebian debian oniguruma_projectphpruby-lang 9y ago An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds write in onigenc_unicode_get_case_fold_codes_by_str…
CVE-2017-9224 critical 9.8 9.8 FIX slesdebian debian oniguruma_projectphp 9y ago An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds read occurs in match_at() during regular expression…
CVE-2017-2800 critical 9.8 10.0 EXPFIX debian debian wolfssl 9y ago A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate validation vulnerabilities, denial of service and pos…
CVE-2017-9214 critical 9.8 9.8 FIX slesdebian debian rhel openvswitchredhat 9y ago In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pu…
CVE-2016-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu zliboracleredhat 9y ago The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
CVE-2016-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu zliboracleredhat 9y ago inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2016-7979 critical 9.8 9.8 FIX slesdebian debian artifex 9y ago Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.
CVE-2016-7978 critical 9.8 9.8 FIX slesdebian debian artifex 9y ago Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.
CVE-2016-5178 critical 9.8 9.8 FIX arch archdebian debiansuse suse google 9y ago arbitrary code execution in chromium
CVE-2017-2520 critical 9.8 9.8 FIX debian debianmacos macos 9y ago An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involve…
CVE-2017-2519 critical 9.8 9.8 FIX debian debianmacos macos 9y ago An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involve…
CVE-2017-2518 critical 9.8 9.8 FIX slesdebian debianmacos macos 9y ago An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involve…
CVE-2017-2513 critical 9.8 9.8 FIX macos macosdebian debian 9y ago An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involve…
CVE-2017-9058 critical 9.8 9.8 FIX arch archdebian debianubuntu ubuntu ytnef_project 9y ago In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
CVE-2017-9055 critical 9.8 9.8 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.
CVE-2017-9054 critical 9.8 9.8 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to…
CVE-2017-9053 critical 9.1 9.1 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in …
CVE-2017-9052 critical 9.8 9.8 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few pl…
CVE-2017-9051 critical 9.8 9.8 FIX debian debian libav 9y ago libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.
CVE-2017-9031 critical 9.8 9.8 FIX debian debian deluge-torrent 9y ago The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which the name of the render file is not associated with any template file.
CVE-2017-6886 critical 9.8 9.8 FIX slesdebian debian libraw 9y ago An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
CVE-2017-8911 critical 9.8 9.8 FIX debian debian tnef_project 9y ago An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
CVE-2017-8798 critical 9.8 10.0 EXPFIX arch archdebian debian miniupnp_project 9y ago Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-5461 critical 9.8 9.8 FIX arch arch slesdebian debian mozilla 9y ago Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of…
CVE-2017-8872 critical 9.1 9.1 FIX slesdebian debian xmlsoft 9y ago The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
CVE-2017-8786 critical 9.8 9.8 FIX slesdebian debian pcre 9y ago pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression.
CVE-2017-7476 critical 9.8 9.8 FIX slesdebian debian gnulib 9y ago Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.
CVE-2016-10243 critical 9.8 9.8 FIX slesdebian debianfedora fedora tug 9y ago TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
CVE-2017-8399 critical 9.8 9.8 FIX debian debian pcre 9y ago PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
CVE-2016-8649 critical 9.1 9.1 FIX slesdebian debian linuxcontainers 9y ago lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's f…
CVE-2017-8378 critical 9.8 9.8 FIX slesdebian debian podofo_project 9y ago Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspe…
CVE-2017-6519 critical 9.1 9.1 FIX debian debian slesubuntu ubuntu avahi 9y ago avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (tra…
CVE-2017-8366 critical 9.8 9.8 FIX arch archdebian debian ettercap_project 9y ago The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other imp…
CVE-2017-8359 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.
CVE-2017-8358 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.
CVE-2017-7895 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possi…
CVE-2017-8305 critical 9.8 9.8 FIX debian debian 13thmonkey 9y ago The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy.
CVE-2017-8287 critical 9.8 9.8 FIX arch arch slesdebian debian freetype 9y ago FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
CVE-2017-8283 critical 9.8 9.8 FIX debian debian debian 9y ago dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct dire…
CVE-2017-8105 critical 9.8 9.8 FIX arch arch slesdebian debian freetype 9y ago FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
CVE-2014-9654 critical 9.8 9.8 FIX debian debian googleicu-project 9y ago The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring tha…