Show filters
484 Total Results
Displaying 281-290 of 484
Sort by:
Attacker Value
Unknown

CVE-2017-12615

Disclosure Date: September 19, 2017 (last updated July 17, 2024)
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Attacker Value
Unknown

CVE-2017-12899

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
Attacker Value
Unknown

CVE-2017-12896

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
Attacker Value
Unknown

CVE-2017-12902

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
Attacker Value
Unknown

CVE-2017-12987

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
Attacker Value
Unknown

CVE-2017-1000251

Disclosure Date: September 12, 2017 (last updated November 26, 2024)
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
Attacker Value
Unknown

CVE-2017-0902

Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
0
Attacker Value
Unknown

CVE-2017-0901

Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
0
Attacker Value
Unknown

CVE-2017-0899

Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
0
Attacker Value
Unknown

CVE-2017-0900

Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
0