CVE-2013-3718
- EPSS 0.52%
- Published 01.11.2019 13:15:11
- Last modified 21.11.2024 01:54:10
evince is missing a check on number of pages which can lead to a segmentation fault
CVE-2014-5220
- EPSS 0.14%
- Published 08.06.2018 17:29:00
- Last modified 21.11.2024 02:11:39
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
CVE-2014-0158
- EPSS 0.51%
- Published 10.04.2018 15:29:00
- Last modified 21.11.2024 02:01:30
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_deco...
CVE-2016-5314
- EPSS 1.1%
- Published 12.03.2018 02:29:00
- Last modified 21.11.2024 02:54:04
Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated...
CVE-2016-1254
- EPSS 3.04%
- Published 05.12.2017 16:29:00
- Last modified 20.04.2025 01:37:25
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
CVE-2014-4616
- EPSS 0.43%
- Published 24.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decod...
CVE-2014-3462
- EPSS 1.09%
- Published 07.08.2017 20:29:00
- Last modified 20.04.2025 01:37:25
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
CVE-2015-5203
- EPSS 0.38%
- Published 02.08.2017 19:29:00
- Last modified 20.04.2025 01:37:25
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5221
- EPSS 0.23%
- Published 25.07.2017 18:29:00
- Last modified 20.04.2025 01:37:25
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
CVE-2015-5300
- EPSS 34.23%
- Published 21.07.2017 14:29:00
- Last modified 20.04.2025 01:37:25
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option,...