CVE-2017-9430
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon0 days
Published on NVDJun 5
1st PoCJun 5
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a command line with a long name argument that is mishandled in a strcpy call for argv[0]. An example threat model is a web application that launches dnstracer with an untrusted name string.
Affected products
n/a · n/apublic PoCs found — 7
githubgithub.com/homjxi0e/CVE-2017-9430★ 0githubgithub.com/j0lama/Dnstracer-1.9-Fix★ 0cve_referencewww.exploit-db.com/exploits/42424/unverifiedcve_referencepacketstormsecurity.com/files/142799/DNSTracer-1.8.1-Buffer-Overflow.htmlunverifiedexploitdbwww.exploit-db.com/exploits/42424unverifiedexploitdbwww.exploit-db.com/exploits/42115unverifiedcve_referencewww.exploit-db.com/exploits/42115/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.