
CVE-2017-5396 – Mozilla: Use-after-free with Media Decoder (MFSA 2017-02)
https://notcve.org/view.php?id=CVE-2017-5396
25 Jan 2017 — A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Vulnerabilidad de uso de memoria previamente liberada en Media Decoder al trabajar con archivos multimedia cuando se lanzan algunos eventos una vez se liberan de la memoria los elementos media. La vulnerabilidad afecta a Thunderbird en versiones anteriores a la 45.7, Fi... • http://rhn.redhat.com/errata/RHSA-2017-0190.html • CWE-416: Use After Free •

CVE-2017-5208 – icoutils: Check_offset overflow on 64-bit systems
https://notcve.org/view.php?id=CVE-2017-5208
24 Jan 2017 — Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. Un desbordamiento de números enteros en el programa wrestool en icoutils en versiones anteriores a la 0.31.1 permite que atacantes remotos provoquen una denegación de servicio (corrupción de memoria) mediante un ejecutable manipulado. Esto ... • http://rhn.redhat.com/errata/RHSA-2017-0837.html • CWE-122: Heap-based Buffer Overflow CWE-190: Integer Overflow or Wraparound •

CVE-2017-3318 – mysql: Server: Error Handling unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3318
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Error Handling). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ... • http://www.debian.org/security/2017/dsa-3767 •

CVE-2017-3244 – mysql: Server: DML unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3244
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 6.5 (Ava... • http://www.debian.org/security/2017/dsa-3767 •

CVE-2017-3317 – mysql: Logging unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3317
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Logging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to caus... • http://www.debian.org/security/2017/dsa-3767 •

CVE-2017-3243 – mysql: Server: Charsets unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3243
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4 (Availability impacts). • http://www.debian.org/security/2017/dsa-3767 •

CVE-2017-3258 – mysql: Server: DDL unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3258
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 6.5 (Ava... • http://www.debian.org/security/2017/dsa-3767 • CWE-20: Improper Input Validation •

CVE-2017-3265 – mysql: unsafe chmod/chown use in init script (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3265
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized acces... • http://www.debian.org/security/2017/dsa-3767 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •

CVE-2017-3291 – mysql: unrestricted mysqld_safe's ledir (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3291
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Packaging). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL ... • http://www.debian.org/security/2017/dsa-3767 • CWE-426: Untrusted Search Path •

CVE-2017-3238 – mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2017)
https://notcve.org/view.php?id=CVE-2017-3238
20 Jan 2017 — Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 6.... • http://www.debian.org/security/2017/dsa-3767 •