CWE-17 · 166 записей
DEPRECATED: Code
CVE этого класса
166 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2015-0240Готовый эксплойт | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x beforsamba · samba · CWE-17 | Критическая10,0 | — | 88,0 % | 23 февр. 2015 г. |
59В плане | CVE-2014-9222Готовый эксплойт | AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gaallegrosoft · rompager · CWE-17 | Критическая10,0 | — | 63,7 % | 24 дек. 2014 г. |
44В плане | CVE-2015-3292Proof of concept | The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) senetapp · oncommand workflow automation · CWE-17 | Критическая10,0 | — | 12,2 % | 31 мая 2015 г. |
43В плане | CVE-2015-4335Эксплойта нет | Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.redislabs · redis · CWE-17 | Критическая10,0 | — | 9,5 % | 9 июн. 2015 г. |
42В плане | CVE-2015-3183Эксплойта нет | The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remotapache · http server · CWE-17 | Средняя5,0 | — | 73,3 % | 20 июл. 2015 г. |
42В плане | CVE-2015-4620Эксплойта нет | name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNisc · bind · CWE-17 | Высокая7,8 | — | 37,9 % | 8 июл. 2015 г. |
42В плане | CVE-2015-1728Эксплойта нет | Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "microsoft · windows media player · CWE-17 | Критическая9,3 | — | 17,6 % | 9 июн. 2015 г. |
41В плане | CVE-2015-2737Эксплойта нет | The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.mozilla · firefox · CWE-17 | Критическая10,0 | — | 2,7 % | 5 июл. 2015 г. |
41В плане | CVE-2015-2738Эксплойта нет | The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x bemozilla · firefox · CWE-17 | Критическая10,0 | — | 2,7 % | 5 июл. 2015 г. |
41В плане | CVE-2015-2734Эксплойта нет | The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x befomozilla · firefox · CWE-17 | Критическая10,0 | — | 2,7 % | 5 июл. 2015 г. |
41В плане | CVE-2015-5887Эксплойта нет | The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a sessapple · mac os x · CWE-17 | Критическая10,0 | — | 2,5 % | 9 окт. 2015 г. |
39Наблюдать | CVE-2016-10481Эксплойта нет | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, Mqualcomm · mdm9607 firmware · CWE-17 | Критическая9,8 | — | 1,2 % | 18 апр. 2018 г. |
38Наблюдать | CVE-2014-9707Готовый эксплойт | EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .embedthis · goahead · CWE-17 | Высокая7,5 | — | 28,2 % | 31 мар. 2015 г. |
38Наблюдать | CVE-2015-2735Эксплойта нет | nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unimozilla · firefox · CWE-17 | Критическая9,3 | — | 3,8 % | 5 июл. 2015 г. |
38Наблюдать | CVE-2015-2736Эксплойта нет | The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird mozilla · firefox · CWE-17 | Критическая9,3 | — | 3,8 % | 5 июл. 2015 г. |
35Наблюдать | CVE-2016-10142Эксплойта нет | An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.ietf · ipv6 · CWE-17 | Высокая8,6 | — | 2,8 % | 14 янв. 2017 г. |
33Наблюдать | CVE-2015-1465Эксплойта нет | The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period flinux · linux kernel · CWE-17 | Высокая7,8 | — | 6,5 % | 5 апр. 2015 г. |
33Наблюдать | CVE-2015-1157Proof of concept | CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Uniapple · iphone os · CWE-17 | Высокая7,8 | — | 5,5 % | 27 мая 2015 г. |
33Наблюдать | CVE-2015-1935Эксплойта нет | The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Wibm · db2 · CWE-17 | Высокая8,0 | — | 3,5 % | 19 июл. 2015 г. |
32Наблюдать | CVE-2015-8027Эксплойта нет | Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, whicnodejs · node.js · CWE-17 | Высокая7,5 | — | 5,4 % | 2 янв. 2016 г. |
32Наблюдать | CVE-2015-1233Эксплойта нет | Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attagoogle · chrome · CWE-17 | Высокая7,5 | — | 5,3 % | 1 апр. 2015 г. |
32Наблюдать | CVE-2015-0847Эксплойта нет | nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a dencanonical · ubuntu linux · CWE-17 | Высокая7,8 | — | 3,1 % | 29 мая 2015 г. |
32Наблюдать | CVE-2014-6386Эксплойта нет | Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47juniper · junos · CWE-17 | Высокая7,8 | — | 2,7 % | 16 янв. 2015 г. |
32Наблюдать | CVE-2015-1452Эксплойта нет | The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers tofortinet · fortios · CWE-17 | Высокая7,8 | — | 1,8 % | 2 февр. 2015 г. |
31Наблюдать | CVE-2015-2743Эксплойта нет | PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workermozilla · firefox · CWE-17 | Высокая7,5 | — | 4,7 % | 5 июл. 2015 г. |
- CVE-2015-024066На этой неделе
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x befor
КритическаяCVSS 10,0Готовый эксплойтEPSS 88 %samba · samba23 февр. 2015 г.
- CVE-2014-922259В плане
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to ga
КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %allegrosoft · rompager24 дек. 2014 г.
- CVE-2015-329244В плане
The installer in NetApp OnCommand Workflow Automation before 2.2.1P1 and 3.x before 3.0P1 sets up the Java Debugging Wire Protocol (JDWP) se
КритическаяCVSS 10,0Proof of conceptEPSS 12 %netapp · oncommand workflow automation31 мая 2015 г.
- CVE-2015-433543В плане
Redis before 2.8.21 and 3.x before 3.0.2 allows remote attackers to execute arbitrary Lua bytecode via the eval command.
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %redislabs · redis9 июн. 2015 г.
- CVE-2015-318342В плане
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remot
СредняяCVSS 5,0Эксплойта нетEPSS 73 %apache · http server20 июл. 2015 г.
- CVE-2015-462042В плане
name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DN
ВысокаяCVSS 7,8Эксплойта нетEPSS 38 %isc · bind8 июл. 2015 г.
- CVE-2015-172842В плане
Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "
КритическаяCVSS 9,3Эксплойта нетEPSS 18 %microsoft · windows media player9 июн. 2015 г.
- CVE-2015-273741В плане
The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %mozilla · firefox5 июл. 2015 г.
- CVE-2015-273841В плане
The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x be
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %mozilla · firefox5 июл. 2015 г.
- CVE-2015-273441В плане
The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x befo
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %mozilla · firefox5 июл. 2015 г.
- CVE-2015-588741В плане
The TLS Handshake Protocol implementation in Secure Transport in Apple OS X before 10.11 accepts a Certificate Request message within a sess
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %apple · mac os x9 окт. 2015 г.
- CVE-2016-1048139Наблюдать
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, M
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %qualcomm · mdm9607 firmware18 апр. 2018 г.
- CVE-2014-970738Наблюдать
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a .
ВысокаяCVSS 7,5Готовый эксплойтEPSS 28 %embedthis · goahead31 мар. 2015 г.
- CVE-2015-273538Наблюдать
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses uni
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %mozilla · firefox5 июл. 2015 г.
- CVE-2015-273638Наблюдать
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %mozilla · firefox5 июл. 2015 г.
- CVE-2016-1014235Наблюдать
An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages.
ВысокаяCVSS 8,6Эксплойта нетEPSS 3 %ietf · ipv614 янв. 2017 г.
- CVE-2015-146533Наблюдать
The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update (RCU) grace period f
ВысокаяCVSS 7,8Эксплойта нетEPSS 6 %linux · linux kernel5 апр. 2015 г.
- CVE-2015-115733Наблюдать
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Uni
ВысокаяCVSS 7,8Proof of conceptEPSS 6 %apple · iphone os27 мая 2015 г.
- CVE-2015-193533Наблюдать
The scalar-function implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and W
ВысокаяCVSS 8,0Эксплойта нетEPSS 4 %ibm · db219 июл. 2015 г.
- CVE-2015-802732Наблюдать
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, whic
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %nodejs · node.js2 янв. 2016 г.
- CVE-2015-123332Наблюдать
Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote atta
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %google · chrome1 апр. 2015 г.
- CVE-2015-084732Наблюдать
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a den
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %canonical · ubuntu linux29 мая 2015 г.
- CVE-2014-638632Наблюдать
Juniper Junos 11.4 before 11.4R8, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, 12.1X47 before 12.1X47
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %juniper · junos16 янв. 2015 г.
- CVE-2015-145232Наблюдать
The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %fortinet · fortios2 февр. 2015 г.
- CVE-2015-274331Наблюдать
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Worker
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %mozilla · firefox5 июл. 2015 г.