Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 685

Количество 54 685

redhat логотип

CVE-2017-18186

почти 9 лет назад

An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18185

почти 9 лет назад

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18184

почти 9 лет назад

An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18183

около 9 лет назад

An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18174

больше 8 лет назад

In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-18079

около 9 лет назад

drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists value can change after it is validated.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-18078

больше 8 лет назад

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2017-18077

больше 9 лет назад

index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-18075

больше 8 лет назад

crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2017-18043

почти 9 лет назад

Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).

CVSS3: 2.8
EPSS: Низкий
redhat логотип

CVE-2017-18030

больше 9 лет назад

The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2017-18029

почти 9 лет назад

In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18028

почти 9 лет назад

In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18027

почти 9 лет назад

In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18022

больше 8 лет назад

In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-18018

больше 8 лет назад

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2017-18017

больше 8 лет назад

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2017-18013

больше 8 лет назад

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-18009

больше 8 лет назад

In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2017-18008

больше 8 лет назад

In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-18186

An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

CVSS3: 3.3
1%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18185

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

CVSS3: 3.3
1%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18184

An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

CVSS3: 3.3
1%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18183

An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-18174

In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.

CVSS3: 5.5
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18079

drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact because the port->exists value can change after it is validated.

CVSS3: 5.5
0%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-18078

systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the fs.protected_hardlinks sysctl is turned off, which allows local users to bypass intended access restrictions via vectors involving a hard link to a file for which the user lacks write access, as demonstrated by changing the ownership of the /etc/passwd file.

CVSS3: 6.7
1%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18077

index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.

CVSS3: 5.3
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-18075

crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.

CVSS3: 5.5
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18043

Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).

CVSS3: 2.8
0%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18030

The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to negative pitch.

CVSS3: 3
0%
Низкий
больше 9 лет назад
redhat логотип
CVE-2017-18029

In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
4%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18028

In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
2%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18027

In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.

CVSS3: 3.3
3%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-18022

In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.

CVSS3: 3.3
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18018

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

CVSS3: 4.2
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18017

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

CVSS3: 6.5
53%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-18013

In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

CVSS3: 7.5
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18009

In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.

CVSS3: 4.4
2%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-18008

In ImageMagick 7.0.7-17 Q16, there is a Memory Leak in ReadPWPImage in coders/pwp.c.

CVSS3: 4.3
3%
Низкий
больше 8 лет назад

Уязвимостей на страницу