CVE-2017-15370
- EPSS 0.8%
- Veröffentlicht 16.10.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
CVE-2017-15371
- EPSS 0.59%
- Veröffentlicht 16.10.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
CVE-2017-15372
- EPSS 0.62%
- Veröffentlicht 16.10.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
CVE-2017-12629
- EPSS 93.89%
- Veröffentlicht 14.10.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...
CVE-2017-2888
- EPSS 2.8%
- Veröffentlicht 11.10.2017 18:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential...
CVE-2017-2887
- EPSS 1.66%
- Veröffentlicht 11.10.2017 18:29:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can cause a stack-based buffer overflow resulting in potential code execution. An attacker can provide a s...
CVE-2017-0903
- EPSS 4.62%
- Veröffentlicht 11.10.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalat...
CVE-2017-15238
- EPSS 0.57%
- Veröffentlicht 11.10.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
CVE-2017-15191
- EPSS 0.92%
- Veröffentlicht 10.10.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.4.0 to 2.4.1, 2.2.0 to 2.2.9, and 2.0.0 to 2.0.15, the DMP dissector could crash. This was addressed in epan/dissectors/packet-dmp.c by validating a string length.
CVE-2017-5637
- EPSS 17.45%
- Veröffentlicht 10.10.2017 01:30:22
- Zuletzt bearbeitet 20.04.2025 01:37:25
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3...