Show filters
284 Total Results
Displaying 161-170 of 284
Sort by:
Attacker Value
Unknown

CVE-2017-14166

Disclosure Date: September 06, 2017 (last updated November 26, 2024)
libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar archive, related to the mishandling of empty strings in the atol8 function in archive_read_support_format_xar.c.
0
Attacker Value
Unknown

CVE-2017-7930

Disclosure Date: August 25, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Data Archive has protocol flaws with the potential to expose change records in the clear and allow a malicious party to spoof a server within a collective.
0
Attacker Value
Unknown

CVE-2017-7934

Disclosure Date: August 25, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017. PI Network Manager using older protocol versions contains a flaw that could allow a malicious user to authenticate with a server and then cause PI Network Manager to behave in an undefined manner.
0
Attacker Value
Unknown

CVE-2017-1000026

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
Attacker Value
Unknown

CVE-2016-3083

Disclosure Date: May 30, 2017 (last updated November 08, 2023)
Apache Hive (JDBC + HiveServer2) implements SSL for plain TCP and HTTP connections (it supports both transport modes). While validating the server's certificate during the connection setup, the client in Apache Hive before 1.2.2 and 2.0.x before 2.0.1 doesn't seem to be verifying the common name attribute of the certificate. In this way, if a JDBC client sends an SSL request to server abc.com, and the server responds with a valid certificate (certified by CA) but issued to xyz.com, the client will accept that as a valid certificate and the SSL handshake will go through.
0
Attacker Value
Unknown

CVE-2016-10349

Disclosure Date: May 01, 2017 (last updated November 26, 2024)
The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
0
Attacker Value
Unknown

CVE-2016-10350

Disclosure Date: May 01, 2017 (last updated November 26, 2024)
The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
0
Attacker Value
Unknown

CVE-2016-10209

Disclosure Date: April 03, 2017 (last updated November 26, 2024)
The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.
0
Attacker Value
Unknown

CVE-2016-8687

Disclosure Date: February 15, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the safe_fprintf function in tar/util.c in libarchive 3.2.1 allows remote attackers to cause a denial of service via a crafted non-printable multibyte character in a filename.
0
Attacker Value
Unknown

CVE-2016-8688

Disclosure Date: February 15, 2017 (last updated November 26, 2024)
The mtree bidder in libarchive 3.2.1 does not keep track of line sizes when extending the read-ahead, which allows remote attackers to cause a denial of service (crash) via a crafted file, which triggers an invalid read in the (1) detect_form or (2) bid_entry function in libarchive/archive_read_support_format_mtree.c.
0