Android suffers from a kernel information disclosure vulnerability in the maxdsm_read function in the maxdsm driver.
9fe66c9d127d43c00ea4b0116eb9c917474d5e6376dce48720e7bba86ceeebdb
Android suffers from a race condition in the max86902 driver sysfs interfaces.
e9f80a6e96632a7efbeb45128bbf886bfd54a33da227b3ccd75a5a8ac9b3d50f
EMC ScaleIO versions prior to 2.0.1.1 suffer from privilege escalation and denial of service vulnerabilities.
d749aee8ebc28fb7622b45b35908b2b2bc362aa44775e89a628bec27bd08668e
Debian Linux Security Advisory 3753-1 - It was discovered that libvncserver, a collection of libraries used to implement VNC/RFB clients and servers, incorrectly processed incoming network packets. This resulted in several heap-based buffer overflows, allowing a rogue server to either cause a DoS by crashing the client, or potentially execute arbitrary code on the client side.
3765364083eeb5d390903842e409e9207be323312ec2bce0e8e728b3ca2b7671
Ubuntu Security Notice 3164-1 - Bjoern Jacke discovered that Exim incorrectly handled DKIM keys. In certain configurations, private DKIM signing keys could be leaked to the log files.
c2586094b5f6fd1850c04f8c9df8ab3a7d0dd8e5752195fd1f23018fceb24c5d
OpenStego is a tool implemented in Java for generic steganography, with support for password-based encryption of the data. It supports plugins for various steganographic algorithms (currently, only Least Significant Bit algorithm is supported for images).
6cf89b9441abe60d8e1bea6dabb8a86ff6c93007f5524678a1f50b3385574dc7
Red Hat Security Advisory 2017-0019-01 - GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Security Fix: Multiple flaws were discovered in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use these flaws to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
fe6f533db94e84e30f264e1240c695fda84a23f54a31e74078edc96970b439ca
Red Hat Security Advisory 2017-0018-01 - GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix: An integer overflow flaw, leading to a heap-based buffer overflow, was found in GStreamer's VMware VMnc video file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
6fcaf8c3af5db702f3f33053e36c1692d78a6e08e5cdfa99e86e7c1e75af58fe
Red Hat Security Advisory 2017-0020-01 - GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Security Fix: Multiple flaws were discovered in GStreamer's FLC/FLI/FLX media file format decoding plug-in. A remote attacker could use these flaws to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
3c90a699086db784048737a3e4535443a70c5c7a9c0dbf19ce9ec8a19e1d9c22
Red Hat Security Advisory 2017-0021-01 - GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix: An integer overflow flaw, leading to a heap-based buffer overflow, was found in GStreamer's VMware VMnc video file format decoding plug-in. A remote attacker could use this flaw to cause an application using GStreamer to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
c42a07008218ec23907f1d8569434ef5fef903adf965f348f623a087bf0c5f79
Broadband DSL modems manufactured by Zyxel and distributed by some European ISPs are vulnerable to a command injection vulnerability when setting the 'NewNTPServer' value using the TR-64 SOAP-based configuration protocol. In the tested case, no authentication is required to set this value on affected DSL modems. This exploit was originally tested on firmware versions up to 2.00(AADU.5)_20150909.
d0f3e308df7f2c60b46816c186b7e07f2aa7c82bc528b215657b9e6e540218cd