CVE-2017-10965: NULL dereference when receiving messages with invalid time stamps CVE-2017-10966: use-after-free