CVE-2017-1000476
- EPSS 0.68%
- Veröffentlicht 03.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:49
ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
CVE-2017-1000501
- EPSS 6.55%
- Veröffentlicht 03.01.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:52
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.
- EPSS 33.58%
- Veröffentlicht 03.01.2018 06:29:00
- Zuletzt bearbeitet 03.01.2025 12:15:25
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other im...
CVE-2017-1000433
- EPSS 2.08%
- Veröffentlicht 02.01.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:44
pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without knowing their password.
CVE-2017-1000422
- EPSS 0.96%
- Veröffentlicht 02.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:42
Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
CVE-2017-1000421
- EPSS 0.5%
- Veröffentlicht 02.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:42
Gifsicle gifview 1.89 and older is vulnerable to a use-after-free in the read_gif function resulting potential code execution
CVE-2017-1000456
- EPSS 0.72%
- Veröffentlicht 02.01.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:46
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
CVE-2017-1000450
- EPSS 2.26%
- Veröffentlicht 02.01.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:45
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. If the image is from remote, may lead to remote code execution or denial of service. This affects Ope...
CVE-2017-1000445
- EPSS 1.76%
- Veröffentlicht 02.01.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:04:45
ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service
CVE-2017-18005
- EPSS 0.36%
- Veröffentlicht 31.12.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.