| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2016-8491 | Cri | 0.59 | 9.1 | 0.00 | Feb 1, 2017 | The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. | |
| CVE-2016-10164 | Cri | 0.64 | 9.8 | 0.04 | Feb 1, 2017 | Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow. | |
| CVE-2016-9420 | Cri | 0.64 | 9.8 | 0.01 | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "loose comparison false positives." | |
| CVE-2016-9416 | Cri | 0.64 | 9.8 | 0.04 | Jan 31, 2017 | SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| CVE-2016-9412 | Cri | 0.64 | 9.8 | 0.03 | Jan 31, 2017 | MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy. | |
| CVE-2016-9403 | Cri | 0.64 | 9.8 | 0.05 | Jan 31, 2017 | newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check. | |
| CVE-2016-9402 | Cri | 0.64 | 9.8 | 0.04 | Jan 31, 2017 | SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| CVE-2015-8974 | Cri | 0.65 | 10.0 | 0.04 | Jan 31, 2017 | SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| CVE-2016-10043 | Cri | 0.71 | 10.0 | 0.38 | Jan 31, 2017 | An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (|) to inject arbitrary OS commands and retrieve the output in the application's responses. Attackers could execute unauthorized commands, which could then be used to disable the software, or read, write, and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner (apache user). | |
| CVE-2016-9132 | Cri | 0.64 | 9.8 | 0.00 | Jan 30, 2017 | In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure. | |
| CVE-2016-6604 | Cri | 0.64 | 9.8 | 0.01 | Jan 30, 2017 | NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382. | |
| CVE-2016-6269 | Cri | 0.59 | 9.1 | 0.02 | Jan 30, 2017 | Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php. | |
| CVE-2017-5611 | Cri | 0.65 | 9.8 | 0.12 | Jan 30, 2017 | SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name. | |
| CVE-2016-10182 | Cri | 0.68 | 9.8 | 0.49 | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. | |
| CVE-2016-10178 | Cri | 0.65 | 9.8 | 0.22 | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command. | |
| CVE-2016-10177 | Cri | 0.65 | 9.8 | 0.20 | Jan 30, 2017 | An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234. | |
| CVE-2016-10176 | Cri | 0.74 | 9.8 | 0.87 | Jan 30, 2017 | The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery questions) and achieve remote code execution. | |
| CVE-2016-10175 | Cri | 0.73 | 9.8 | 0.82 | Jan 30, 2017 | The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions. | |
| CVE-2016-10174 | Cri | 0.86 | 9.8 | 0.91 | KEV | Jan 30, 2017 | The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution. |
| CVE-2017-5486 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). | |
| CVE-2017-5485 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap(). | |
| CVE-2017-5484 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2017 | The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print(). | |
| CVE-2017-5483 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse(). | |
| CVE-2017-5482 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575. | |
| CVE-2017-5342 | Cri | 0.64 | 9.8 | 0.04 | Jan 28, 2017 | In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print(). | |
| CVE-2017-5341 | Cri | 0.64 | 9.8 | 0.04 | Jan 28, 2017 | The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print(). | |
| CVE-2017-5205 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). | |
| CVE-2017-5204 | Cri | 0.64 | 9.8 | 0.02 | Jan 28, 2017 | The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). | |
| CVE-2017-5203 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). | |
| CVE-2017-5202 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). | |
| CVE-2016-8575 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482. | |
| CVE-2016-8574 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print(). | |
| CVE-2016-7993 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM). | |
| CVE-2016-7992 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print(). | |
| CVE-2016-7986 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions. | |
| CVE-2016-7985 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print(). | |
| CVE-2016-7984 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print(). | |
| CVE-2016-7983 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). | |
| CVE-2016-7975 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print(). | |
| CVE-2016-7974 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions. | |
| CVE-2016-7973 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions. | |
| CVE-2016-7940 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions. | |
| CVE-2016-7939 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions. | |
| CVE-2016-7938 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame(). | |
| CVE-2016-7937 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print(). | |
| CVE-2016-7936 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print(). | |
| CVE-2016-7935 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print(). | |
| CVE-2016-7934 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print(). | |
| CVE-2016-7933 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print(). | |
| CVE-2016-7932 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2017 | The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum(). |
- risk 0.59cvss 9.1epss 0.00
The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell.
- risk 0.64cvss 9.8epss 0.04
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via (1) the number of extensions or (2) their concatenated length in a crafted XPM file, which triggers a heap-based buffer overflow.
- risk 0.64cvss 9.8epss 0.01
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "loose comparison false positives."
- risk 0.64cvss 9.8epss 0.04
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.64cvss 9.8epss 0.03
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.
- risk 0.64cvss 9.8epss 0.05
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.
- risk 0.64cvss 9.8epss 0.04
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.65cvss 10.0epss 0.04
SQL injection vulnerability in the Group Promotions module in the admin control panel in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- risk 0.71cvss 10.0epss 0.38
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (|) to inject arbitrary OS commands and retrieve the output in the application's responses. Attackers could execute unauthorized commands, which could then be used to disable the software, or read, write, and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner (apache user).
- risk 0.64cvss 9.8epss 0.00
In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. Some API callers may use the returned (incorrect and attacker controlled) length field in a way which later causes memory corruption or other failure.
- risk 0.64cvss 9.8epss 0.01
NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382.
- risk 0.59cvss 9.1epss 0.02
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt_adhocquery_ajaxhandler.php, (2) log_mgt_ajaxhandler.php, (3) log_mgt_ajaxhandler.php or (4) tf parameter to wcs_bwlists_handler.php.
- risk 0.65cvss 9.8epss 0.12
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
- risk 0.68cvss 9.8epss 0.49
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.
- risk 0.65cvss 9.8epss 0.22
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
- risk 0.65cvss 9.8epss 0.20
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services provide logins to admin with the password admin and root with the password 1234.
- risk 0.74cvss 9.8epss 0.87
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery questions) and achieve remote code execution.
- risk 0.73cvss 9.8epss 0.82
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.
- risk 0.86cvss 9.8epss 0.91
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.
- risk 0.64cvss 9.8epss 0.01
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
- risk 0.64cvss 9.8epss 0.01
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap().
- risk 0.64cvss 9.8epss 0.02
The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().
- risk 0.64cvss 9.8epss 0.01
The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse().
- risk 0.64cvss 9.8epss 0.01
The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.
- risk 0.64cvss 9.8epss 0.04
In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().
- risk 0.64cvss 9.8epss 0.04
The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().
- risk 0.64cvss 9.8epss 0.01
The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
- risk 0.64cvss 9.8epss 0.02
The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
- risk 0.64cvss 9.8epss 0.01
The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
- risk 0.64cvss 9.8epss 0.01
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
- risk 0.64cvss 9.8epss 0.01
The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482.
- risk 0.64cvss 9.8epss 0.01
The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print().
- risk 0.64cvss 9.8epss 0.01
A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM).
- risk 0.64cvss 9.8epss 0.01
The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().
- risk 0.64cvss 9.8epss 0.01
The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.
- risk 0.64cvss 9.8epss 0.01
The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().
- risk 0.64cvss 9.8epss 0.01
The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().
- risk 0.64cvss 9.8epss 0.01
The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
- risk 0.64cvss 9.8epss 0.01
The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
- risk 0.64cvss 9.8epss 0.01
The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.
- risk 0.64cvss 9.8epss 0.01
The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.
- risk 0.64cvss 9.8epss 0.01
The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions.
- risk 0.64cvss 9.8epss 0.01
The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions.
- risk 0.64cvss 9.8epss 0.01
The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame().
- risk 0.64cvss 9.8epss 0.01
The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print().
- risk 0.64cvss 9.8epss 0.01
The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print().
- risk 0.64cvss 9.8epss 0.01
The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print().
- risk 0.64cvss 9.8epss 0.01
The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print().
- risk 0.64cvss 9.8epss 0.01
The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print().
- risk 0.64cvss 9.8epss 0.01
The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum().