Latest CVE Feed
-
7.5
HIGHCVE-2017-9353
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9352
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bazaar dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-bzr.c by ensuring that backwards parsing cannot occur.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9351
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9350
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9349
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9348
In Wireshark 2.2.0 to 2.2.6, the DOF dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-dof.c by validating a size value.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9347
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/asn1/ros/packet-ros-template.c by validating an OID.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9346
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the SoulSeek dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-slsk.c by making loop bounds more explicit.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9345
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DNS dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-dns.c by trying to detect self-referencing pointers.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9344
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the Bluetooth L2CAP dissector could divide by zero. This was addressed in epan/dissectors/packet-btl2cap.c by validating an interval value.... Read more
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9343
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the MSNIP dissector misuses a NULL pointer. This was addressed in epan/dissectors/packet-msnip.c by validating an IPv4 address.... Read more
Affected Products : wireshark- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9060
Memory leak in the virtio_gpu_set_scanout function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (memory consumption) via a large number of "VIRTIO_GPU_CMD_SET_SCANOUT:" commands.... Read more
Affected Products : qemu- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8386
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privile... Read more
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7999
Atlassian Eucalyptus before 4.4.1, when in EDGE mode, allows remote authenticated users with certain privileges to cause a denial of service (E2 service outage) via unspecified vectors.... Read more
Affected Products : eucalyptus- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7384
Cross-site scripting (XSS) vulnerability in FlipBuilder Flip PDF allows remote attackers to inject arbitrary web script or HTML via the currentHTMLURL parameter.... Read more
Affected Products : flip_pdf- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6512
Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loosening logic.... Read more
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-6531
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.... Read more
Affected Products : pan-os- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-5473
Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with SYSTEM privilege... Read more
Affected Products : syncthru_6- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.... Read more
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3127
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.... Read more
Affected Products : fortios- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025