Show filters
188 Total Results
Displaying 121-130 of 188
Sort by:
Attacker Value
Unknown
CVE-2018-8013
Disclosure Date: May 24, 2018 (last updated November 08, 2023)
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
0
Attacker Value
Unknown
CVE-2018-5205
Disclosure Date: January 06, 2018 (last updated November 26, 2024)
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
0
Attacker Value
Unknown
CVE-2017-16612
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcursor.c in Wayland through 1.14.0.
0
Attacker Value
Unknown
CVE-2017-16611
Disclosure Date: December 01, 2017 (last updated November 26, 2024)
In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.
0
Attacker Value
Unknown
CVE-2017-14746
Disclosure Date: November 27, 2017 (last updated November 26, 2024)
Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
0
Attacker Value
Unknown
CVE-2017-15275
Disclosure Date: November 27, 2017 (last updated November 26, 2024)
Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
0
Attacker Value
Unknown
CVE-2017-14176
Disclosure Date: November 27, 2017 (last updated November 26, 2024)
Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-9800, CVE-2017-12836, CVE-2017-12976, CVE-2017-16228, CVE-2017-1000116, and CVE-2017-1000117.
0
Attacker Value
Unknown
CVE-2017-14177
Disclosure Date: November 15, 2017 (last updated November 26, 2024)
Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1324.
0
Attacker Value
Unknown
CVE-2017-14180
Disclosure Date: November 15, 2017 (last updated November 26, 2024)
Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion or possibly gain root privileges, a different vulnerability than CVE-2017-14179.
0
Attacker Value
Unknown
CVE-2017-14179
Disclosure Date: November 15, 2017 (last updated November 26, 2024)
Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers.
0