3 results (0.007 seconds)

CVSS: 9.8EPSS: 2%CPEs: 260EXPL: 0

OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of this issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. OpenSLP, como es usado en ESXi y los dispositivos Horizon DaaS, presenta un problema de sobrescritura de la pila. VMware ha evaluado la gravedad de este problema para estar en el rango de gravedad Crítica con una puntuación base máxima CVSSv3 de 9.8. A heap overflow vulnerability was found in OpenSLP. • http://www.openwall.com/lists/oss-security/2019/12/10/2 http://www.openwall.com/lists/oss-security/2019/12/11/2 http://www.vmware.com/security/advisories/VMSA-2019-0022.html https://access.redhat.com/errata/RHSA-2019:4240 https://access.redhat.com/errata/RHSA-2020:0199 https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DA3LYAJ2NRKMOZLZOQNDJ5TNQRFMWGHF https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPXXJZLPLAQU • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •

CVSS: 7.5EPSS: 1%CPEs: 15EXPL: 0

Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets. • http://secunia.com/advisories/14561 http://secunia.com/advisories/22128 http://www.gentoo.org/security/en/glsa/glsa-200503-25.xml http://www.mandriva.com/security/advisories?name=MDKSA-2005:055 http://www.novell.com/linux/security/advisories/2005_15_openslp.html http://www.securityfocus.com/archive/1/447537/100/0/threaded http://www.securityfocus.com/bid/12792 http://www.vupen.com/english/advisories/2006/3879 https://exchange.xforce.ibmcloud.com/vulnerabilities/19683 https:/&# •

CVSS: 2.1EPSS: 0%CPEs: 1EXPL: 0

Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file. Vulnerabilidad de enlaces simbólicos en el script slpd slpd.all_init de OpenSLP anteriores a 1.0.11 permite a usuarios locales sobreescribir ficheros arbitrarios mediante el fichero temporal route.check. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000723 http://marc.info/?l=bugtraq&m=106123103606336&w=2 •