Latest CVE Feed
-
6.1
MEDIUMCVE-2017-7271
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7191
The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.... Read more
Affected Products : irssi- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7183
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.... Read more
Affected Products : extraputty- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6542
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded ag... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6464
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration directive.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6463
NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a :config directive, related to the unpeer option.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6462
Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via a crafted /dev/datum device.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6460
Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote servers have unspecified impact via a long flagstr variable in a restriction list response.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6459
The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via vectors related to an argument with multiple null bytes.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6458
Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenticated users to have unspecified impact via a long variable.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6455
NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the PPSAPI_DLLS environment variable.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6452
Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via an application path on the command line.... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6451
The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly handle the return value of the snprintf function, which allows local users to execute arbitrary code via unspecified vectors, which tri... Read more
Affected Products : ntp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9243
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4912
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.... Read more
Affected Products : openslp- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10225
The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-8764
Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.... Read more
Affected Products : freeradius- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-8763
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.... Read more
Affected Products : freeradius- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-8762
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.... Read more
Affected Products : freeradius- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8010
Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025