CVE-2017-5957

CVE-2017-5957

Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.

Source: CVE-2017-5957

CVE-2017-5668

CVE-2017-5668

bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.

Source: CVE-2017-5668

CVE-2016-9368 (xcomfort_ethernet_communication_interface)

CVE-2016-9368 (xcomfort_ethernet_communication_interface)

An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating.

Source: CVE-2016-9368 (xcomfort_ethernet_communication_interface)

CVE-2017-6398 (interscan_messaging_security_virtual_appliance)

CVE-2017-6398 (interscan_messaging_security_virtual_appliance)

An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminal command in the context of the web server user (which is root). Besides, the default installation of IMSVA comes with default administrator credentials. The saveCert.imss endpoint takes several user inputs and performs blacklisting. After that, it uses them as arguments to a predefined operating-system command without proper sanitization. However, because of an improper blacklisting rule, it’s possible to inject arbitrary commands into it.

Source: CVE-2017-6398 (interscan_messaging_security_virtual_appliance)

CVE-2017-6883 (foxit_reader, phantompdf)

CVE-2017-6883 (foxit_reader, phantompdf)

The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

Source: CVE-2017-6883 (foxit_reader, phantompdf)

CVE-2017-6874 (linux_kernel)

CVE-2017-6874 (linux_kernel)

Race condition in kernel/ucount.c in the Linux kernel through 4.10.2 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls that leverage certain decrement behavior that causes incorrect interaction between put_ucounts and get_ucounts.

Source: CVE-2017-6874 (linux_kernel)