CVE-2017-5938
- EPSS 0.63%
- Veröffentlicht 15.03.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
CVE-2016-10070
- EPSS 0.62%
- Veröffentlicht 03.03.2017 18:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
CVE-2016-10065
- EPSS 0.26%
- Veröffentlicht 03.03.2017 17:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
CVE-2016-7969
- EPSS 4%
- Veröffentlicht 03.03.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
CVE-2016-7972
- EPSS 3.15%
- Veröffentlicht 03.03.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
CVE-2016-10064
- EPSS 0.28%
- Veröffentlicht 02.03.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
CVE-2016-10068
- EPSS 0.81%
- Veröffentlicht 02.03.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.
CVE-2016-9830
- EPSS 0.6%
- Veröffentlicht 01.03.2017 20:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.
CVE-2016-10207
- EPSS 1.69%
- Veröffentlicht 28.02.2017 18:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.
CVE-2016-8866
- EPSS 0.48%
- Veröffentlicht 15.02.2017 19:59:01
- Zuletzt bearbeitet 13.05.2026 00:24:29
The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because...