Vulnerabilities
Vulnerable Software
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (traffic amplification) and may cause information leakage by obtaining potentially sensitive information from the responding device via port-5353 UDP packets. NOTE: this may overlap CVE-2015-2809.
CVSS Score
9.1
EPSS Score
0.015
Published
2017-05-01
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
CVSS Score
8.8
EPSS Score
0.014
Published
2017-02-13
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
CVSS Score
7.5
EPSS Score
0.024
Published
2017-02-09
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVSS Score
9.8
EPSS Score
0.161
Published
2017-02-09
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVSS Score
5.5
EPSS Score
0.004
Published
2017-01-27


Contact Us

Shodan ® - All rights reserved