CVE-2017-14448
- EPSS 1.67%
- Veröffentlicht 24.04.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:12:48
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to...
CVE-2017-14449
- EPSS 0.61%
- Veröffentlicht 24.04.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:12:49
A double-Free vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a Double-Free situation to occur. An attacker can display a specially crafted image to trigger this vulnerability...
CVE-2017-14450
- EPSS 0.77%
- Veröffentlicht 24.04.2018 19:29:01
- Zuletzt bearbeitet 21.11.2024 03:12:49
A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer overflow on a global section. An attacker can display an image to trigger this vulnerability.
CVE-2017-12081
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:47
An exploitable integer overflow exists in the upgrade of a legacy Mesh attribute of the Blender open-source 3d creation suite v2.78c. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for cod...
CVE-2017-12082
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:47
An exploitable integer overflow exists in the 'CustomData' Mesh loading functionality of the Blender open-source 3d creation suite. A .blend file with a specially crafted external data file can cause an integer overflow resulting in a buffer overflow...
CVE-2017-12086
- EPSS 0.79%
- Veröffentlicht 24.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:08:48
An exploitable integer overflow exists in the 'BKE_mesh_calc_normals_tessface' functionality of the Blender open-source 3d creation suite. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow fo...
CVE-2017-7651
- EPSS 23.23%
- Veröffentlicht 24.04.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:22
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.
CVE-2018-10323
- EPSS 0.08%
- Veröffentlicht 24.04.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:41:13
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image.
CVE-2016-9601
- EPSS 0.45%
- Veröffentlicht 24.04.2018 01:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:29
ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an ...
CVE-2018-1106
- EPSS 0.03%
- Veröffentlicht 23.04.2018 20:29:14
- Zuletzt bearbeitet 21.11.2024 03:59:11
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed packages. A local attacker can use this vulnerability to install vulnerable packages to further compromise a...