Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 892

Количество 79 892

ubuntu логотип

CVE-2017-11141

около 9 лет назад

The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11140

около 9 лет назад

The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11139

около 9 лет назад

GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11126

около 9 лет назад

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, a similar issue to CVE-2017-9870.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11119

около 9 лет назад

The chk_mem_access function in cpu/nes6502/nes6502.c in libnosefart.a in Nosefart 2.9-mls allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted nsf file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11114

около 9 лет назад

The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11113

около 9 лет назад

In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11112

около 9 лет назад

In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11111

около 9 лет назад

In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11110

около 9 лет назад

The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11109

около 9 лет назад

Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11108

около 9 лет назад

tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11107

около 9 лет назад

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2017-11104

около 9 лет назад

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2017-11103

около 9 лет назад

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-11102

около 9 лет назад

The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data structure.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2017-11101

около 9 лет назад

When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11100

около 9 лет назад

When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11099

около 9 лет назад

When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-11098

около 9 лет назад

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-11141

The ReadMATImage function in coders\mat.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted MAT file, related to incorrect ordering of a SetImageExtent call.

CVSS3: 6.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11140

The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.

CVSS3: 5.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11139

GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.

CVSS3: 9.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11126

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type != 2" case, a similar issue to CVE-2017-9870.

CVSS3: 5.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11119

The chk_mem_access function in cpu/nes6502/nes6502.c in libnosefart.a in Nosefart 2.9-mls allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted nsf file.

CVSS3: 5.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11114

The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.

CVSS3: 5.5
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11113

In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11112

In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to process untrusted terminfo data.

CVSS3: 7.5
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11111

In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

CVSS3: 7.8
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11110

The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.

CVSS3: 7.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11109

Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.

CVSS3: 7.8
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11108

tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The crash occurs in the EXTRACT_16BITS function, called from the stp_print function for the Spanning Tree Protocol.

CVSS3: 7.5
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11107

phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.

CVSS3: 6.1
2%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11104

Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.

CVSS3: 5.9
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11103

Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE is only for Heimdal and other products that embed Heimdal code; it does not apply to other instances in which this part of the Kerberos 5 protocol specification is violated.

CVSS3: 8.1
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11102

The ReadOneJNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (application crash) during JNG reading via a zero-length color_image data structure.

CVSS3: 7.5
3%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11101

When SWFTools 0.9.2 processes a crafted file in swfcombine, it can lead to a NULL Pointer Dereference in the swf_Relocate() function in lib/modules/swftools.c.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11100

When SWFTools 0.9.2 processes a crafted file in swfextract, it can lead to a NULL Pointer Dereference in the swf_FoldSprite() function in lib/rxfswf.c.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11099

When SWFTools 0.9.2 processes a crafted file in wav2swf, it can lead to a Segmentation Violation in the wav_convert2mono() function in lib/wav.c.

CVSS3: 8.8
1%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2017-11098

When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.

CVSS3: 8.8
1%
Низкий
около 9 лет назад

Уязвимостей на страницу