Show filters
484 Total Results
Displaying 281-290 of 484
Sort by:
Attacker Value
Unknown
CVE-2017-12615
Disclosure Date: September 19, 2017 (last updated July 17, 2024)
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
0
Attacker Value
Unknown
CVE-2017-12899
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().
0
Attacker Value
Unknown
CVE-2017-12896
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
0
Attacker Value
Unknown
CVE-2017-12902
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.
0
Attacker Value
Unknown
CVE-2017-12987
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().
0
Attacker Value
Unknown
CVE-2017-1000251
Disclosure Date: September 12, 2017 (last updated November 26, 2024)
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
0
Attacker Value
Unknown
CVE-2017-0902
Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.
0
Attacker Value
Unknown
CVE-2017-0901
Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
0
Attacker Value
Unknown
CVE-2017-0899
Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
0
Attacker Value
Unknown
CVE-2017-0900
Disclosure Date: August 31, 2017 (last updated November 26, 2024)
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.
0