CVE-2014-4914
- EPSS 3.44%
- Veröffentlicht 29.12.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2017-17912
- EPSS 0.83%
- Veröffentlicht 27.12.2017 17:08:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.
CVE-2017-17913
- EPSS 0.46%
- Veröffentlicht 27.12.2017 17:08:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.
CVE-2017-17914
- EPSS 0.27%
- Veröffentlicht 27.12.2017 17:08:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.7-16 Q16, a vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service (ReadOneMNGImage large loop) via a crafted mng image file.
CVE-2017-17915
- EPSS 0.69%
- Veröffentlicht 27.12.2017 17:08:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
CVE-2017-17935
- EPSS 0.33%
- Veröffentlicht 27.12.2017 17:08:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a crafted packet that ...
CVE-2017-17879
- EPSS 1.34%
- Veröffentlicht 27.12.2017 17:08:21
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
CVE-2017-17852
- EPSS 0.12%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 20.04.2025 01:37:25
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging mishandling of 32-bit ALU ops.
CVE-2017-17853
- EPSS 0.13%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 20.04.2025 01:37:25
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect BPF_RSH signed bounds calculations.
CVE-2017-17854
- EPSS 0.13%
- Veröffentlicht 27.12.2017 17:08:20
- Zuletzt bearbeitet 20.04.2025 01:37:25
kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or possibly have unspecified other impact by leveraging unrestricted integer values for pointer arithmet...