Latest CVE Feed
-
7.8
HIGHCVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x4000000... Read more
Affected Products : linux_kernel- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2017-1000369
Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunction with other issues allows attackers to cause arbitrary code execution. This affects exim version 4.89 and earlier. Please note that... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1000366
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to gli... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1000365
The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_INFINITY (1/4 of the size), but does not take the argument and environment pointers into account, which allows attackers to bypass this... Read more
Affected Products : linux_kernel- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-1000364
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficiently large and can be "jumped" over (the stack guard page is bypassed), this affects Linux Kernel versions 4.11.5 and earlier (the stac... Read more
Affected Products : linux_kernel- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9759
SQL Injection exists in admin/index.php in Zenbership 1.0.8 via the filters array parameter, exploitable by a privileged account.... Read more
Affected Products : zenbership- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9757
IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated users, or through CSRF.... Read more
Affected Products : ipfire- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.... Read more
Affected Products : nuevomailer- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-4987
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on th... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-4985
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user may potentially escalate their privileges to root due to authorization checks not being performed on certain perl scripts. This... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-4984
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an a... Read more
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9756
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demons... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9755
opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of registers for bnd mode, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted bina... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9754
The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and a... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9753
The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which allows remote attackers to cause a denial of service (buffe... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9752
bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a cra... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9751
opcodes/rl78-decode.opc in GNU Binutils 2.28 has an unbounded GETBYTE macro, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonst... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9750
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9749
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9748
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unsp... Read more
Affected Products : binutils- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025