CVE-2017-16546
- EPSS 0.59%
- Veröffentlicht 05.11.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or po...
CVE-2017-16541
- EPSS 4.53%
- Veröffentlicht 04.11.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: T...
CVE-2017-16532
- EPSS 0.09%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 20.04.2025 01:37:25
The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB devic...
CVE-2017-16533
- EPSS 0.11%
- Veröffentlicht 04.11.2017 01:29:37
- Zuletzt bearbeitet 20.04.2025 01:37:25
The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-16525
- EPSS 0.1%
- Veröffentlicht 04.11.2017 01:29:36
- Zuletzt bearbeitet 20.04.2025 01:37:25
The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted USB...
CVE-2017-16526
- EPSS 0.11%
- Veröffentlicht 04.11.2017 01:29:36
- Zuletzt bearbeitet 20.04.2025 01:37:25
drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-16527
- EPSS 0.12%
- Veröffentlicht 04.11.2017 01:29:36
- Zuletzt bearbeitet 20.04.2025 01:37:25
sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-16529
- EPSS 0.12%
- Veröffentlicht 04.11.2017 01:29:36
- Zuletzt bearbeitet 20.04.2025 01:37:25
The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-16516
- EPSS 1.55%
- Veröffentlicht 03.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating...
CVE-2017-16352
- EPSS 31.37%
- Veröffentlicht 01.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to...