NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87338  CVE-2017-9780  In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacker run the setuid executable or write to the world-writable location. In the case of the system helper component, files deployed as part of the app are owned by root, so in the worst case they could be setuid root.    7.2  High  2017-07-18  2017-07-03  View
87337  CVE-2017-9778  GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.    4.3  Medium  2017-07-18  2017-06-29  View
87336  CVE-2017-9776  Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.    6.8  Medium  2017-07-18  2017-06-29  View
87335  CVE-2017-9775  Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.    4.3  Medium  2017-07-18  2017-06-29  View
87334  CVE-2017-9774  Remote Code Execution was found in Horde_Image 2.x before 2.5.0 via a crafted GET request. Exploitation requires authentication.    6.5  Medium  2017-07-18  2017-07-03  View

Page 25 of 17672, showing 5 records out of 88360 total, starting on record 121, ending on 125

Actions