CVE-2017-16353
- EPSS 32.26%
- Veröffentlicht 01.11.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is ...
CVE-2017-1000257
- EPSS 1.09%
- Veröffentlicht 31.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. l...
CVE-2017-1000256
- EPSS 0.78%
- Veröffentlicht 31.10.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libvirt version 2.3.0 and later is vulnerable to a bad default configuration of "verify-peer=no" passed to QEMU by libvirt resulting in a failure to validate SSL/TLS certificates by default.
CVE-2017-16227
- EPSS 1.46%
- Veröffentlicht 29.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDATE messages, because AS_PATH size calculation for long paths counts certain bytes twice and consequent...
CVE-2017-15953
- EPSS 0.27%
- Veröffentlicht 28.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.
CVE-2017-15954
- EPSS 0.31%
- Veröffentlicht 28.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processing a malformed CUE (.cue) file.
CVE-2017-15955
- EPSS 0.25%
- Veröffentlicht 28.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to an "Access violation near NULL on destination operand" and crash when processing a malformed CUE (.cue) file.
CVE-2017-13089
- EPSS 73.11%
- Veröffentlicht 27.10.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the ...
CVE-2017-13090
- EPSS 8.14%
- Veröffentlicht 27.10.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chunk's length, but doesn't check that the chunk length is a non-negative ...
CVE-2017-15930
- EPSS 0.77%
- Veröffentlicht 27.10.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.