Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2017-12666

около 9 лет назад

ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12665

около 9 лет назад

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12664

около 9 лет назад

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12663

около 9 лет назад

ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12662

около 9 лет назад

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12654

около 9 лет назад

The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12652

около 7 лет назад

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2017-12644

около 9 лет назад

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadDCMImage in coders\dcm.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12643

около 9 лет назад

ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12642

около 9 лет назад

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMPCImage in coders\mpc.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12641

около 9 лет назад

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12640

около 9 лет назад

ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2017-12634

почти 9 лет назад

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-12633

почти 9 лет назад

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-12629

почти 9 лет назад

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

CVSS3: 9.8
EPSS: Критический
redhat логотип

CVE-2017-12627

больше 8 лет назад

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2017-12626

больше 8 лет назад

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2017-12624

почти 9 лет назад

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2017-12621

почти 9 лет назад

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL. This could lead to XML External Entity (XXE) attacks in Apache Commons Jelly before 1.0.1.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2017-12618

почти 9 лет назад

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2017-12666

ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteINLINEImage in coders/inline.c.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12665

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePICTImage in coders/pict.c.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12664

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePALMImage in coders/palm.c.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12663

ImageMagick 7.0.6-2 has a memory leak vulnerability in WriteMAPImage in coders/map.c.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12662

ImageMagick 7.0.6-2 has a memory leak vulnerability in WritePDFImage in coders/pdf.c.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12654

The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12652

libpng before 1.6.32 does not properly check the length of chunks against the user limit.

CVSS3: 3.7
4%
Низкий
около 7 лет назад
redhat логотип
CVE-2017-12644

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadDCMImage in coders\dcm.c.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12643

ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 3.3
3%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12642

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadMPCImage in coders\mpc.c.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12641

ImageMagick 7.0.6-1 has a memory leak vulnerability in ReadOneJNGImage in coders\png.c.

CVSS3: 3.3
1%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12640

ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.

CVSS3: 3.3
2%
Низкий
около 9 лет назад
redhat логотип
CVE-2017-12634

The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CVSS3: 7.5
7%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-12633

The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-serialisation vulnerability. De-serializing untrusted data can lead to security flaws.

CVSS3: 7.5
7%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-12629

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is NOT vulnerable to this. Note that the XML external entity expansion vulnerability occurs in the XML Query Parser which is available, by default, for any query request with parameters deftype=xmlparser and can be exploited to upload malicious data to the /upload request handler or as Blind XXE using ftp wrapper in order to read arbitrary local files from the Solr server. Note also that the second vulnerability relates to remote code execution using the RunExecutableListener available on all affected versions of Solr.

CVSS3: 9.8
92%
Критический
почти 9 лет назад
redhat логотип
CVE-2017-12627

In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer dereference under certain conditions.

CVSS3: 7.5
8%
Низкий
больше 8 лет назад
redhat логотип
CVE-2017-12626

Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsing crafted WMF, EMF, MSG and macros (POI bugs 61338 and 61294), and 2) Out of Memory Exceptions while parsing crafted DOC, PPT and XLS (POI bugs 52372 and 61295).

CVSS3: 5.3
10%
Средний
больше 8 лет назад
redhat логотип
CVE-2017-12624

Apache CXF supports sending and receiving attachments via either the JAX-WS or JAX-RS specifications. It is possible to craft a message attachment header that could lead to a Denial of Service (DoS) attack on a CXF web service provider. Both JAX-WS and JAX-RS services are vulnerable to this attack. From Apache CXF 3.2.1 and 3.1.14, message attachment headers that are greater than 300 characters will be rejected by default. This value is configurable via the property "attachment-max-header-size".

CVSS3: 5.3
4%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-12621

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used in the body of the Jelly file, during parser instantiation the parser will attempt to connect to said URL. This could lead to XML External Entity (XXE) attacks in Apache Commons Jelly before 1.0.1.

CVSS3: 9.8
9%
Низкий
почти 9 лет назад
redhat логотип
CVE-2017-12618

Apache Portable Runtime Utility (APR-util) 1.6.0 and prior fail to validate the integrity of SDBM database files used by apr_sdbm*() functions, resulting in a possible out of bound read access. A local user with write access to the database can make a program or process using these functions crash, and cause a denial of service.

CVSS3: 5.5
1%
Низкий
почти 9 лет назад

Уязвимостей на страницу