ZeroHour

Vulnerabilities

19 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-17806
+1 in the same advisory: …17805
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowin

The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.

NVD description · AI analysis pending
7.8<1%
  • linux linux kernel
  • linux debian linux
  • linux leap
  • +1 more
CVE-2016-1254
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

NVD description · AI analysis pending
7.53%
  • torproject tor
  • torproject debian linux
  • torproject fedora
  • +1 more
CVE-2016-9961
+1 in the same advisory: …9960
game-music-emu before 0.6.1 mishandles unspecified integer values.

game-music-emu before 0.6.1 mishandles unspecified integer values.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • game-music-emu project game-music-emu
  • game-music-emu project fedora
  • game-music-emu project leap
  • +1 more
CVE-2016-9959
+2 in the same advisory: …9958 …9957
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

NVD description · AI analysis pending
7.82% PoC
  • opensuse leap
  • opensuse opensuse
  • opensuse linux enterprise
  • +1 more
CVE-2017-6542
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol messag

The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect to the Unix-domain socket representing the forwarded agent connection, which trigger a buffer overflow.

NVD description · AI analysis pending
9.822%
  • putty putty
  • putty leap
CVE-2016-7797
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated conn

Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.

NVD description · AI analysis pending
7.53%
  • clusterlabs pacemaker
  • clusterlabs leap
  • clusterlabs linux enterprise high availability
  • +1 more
CVE-2016-10048
+1 in the same advisory: …9556
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.

Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.

NVD description · AI analysis pending
7.5
group max
7%
  • imagemagick imagemagick
  • imagemagick leap
CVE-2017-5938
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to in

Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.

NVD description · AI analysis pending
6.11%
  • debian debian linux
  • debian leap
  • debian viewvc
CVE-2016-10068
+1 in the same advisory: …10069
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted

The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.

NVD description · AI analysis pending
5.52%
  • imagemagick imagemagick
  • imagemagick leap
CVE-2016-9436
+1 in the same advisory: …9435
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file,

parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a tag.

NVD description · AI analysis pending
6.53%
  • opensuse leap
  • opensuse w3m
CVE-2016-5316
+1 in the same advisory: …5317
Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a

Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.

NVD description · AI analysis pending
6.52%
  • libtiff libtiff
  • libtiff opensuse
  • libtiff leap