CVE-2014-3587
- EPSS 18.72%
- Veröffentlicht 23.08.2014 01:55:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a craf...
CVE-2014-0207
- EPSS 8.85%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...
- EPSS 43.75%
- Veröffentlicht 09.07.2014 11:07:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal...
- EPSS 10.25%
- Veröffentlicht 03.07.2014 14:55:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. N...
- EPSS 1.53%
- Veröffentlicht 24.03.2014 16:31:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a cra...
CVE-2012-1571
- EPSS 0.18%
- Veröffentlicht 17.07.2012 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
CVE-2009-3930
- EPSS 0.88%
- Veröffentlicht 10.11.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file that triggers a buffer overflow.
CVE-2009-1515
- EPSS 4.18%
- Veröffentlicht 04.05.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NO...