- EPSS 3.22%
- Veröffentlicht 12.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remot...
CVE-2017-14341
- EPSS 0.61%
- Veröffentlicht 12.09.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
CVE-2017-14314
- EPSS 0.76%
- Veröffentlicht 12.09.2017 00:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and application crash) via a crafted file.
CVE-2017-7650
- EPSS 1.11%
- Veröffentlicht 11.09.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be ...
CVE-2017-14223
- EPSS 0.85%
- Veröffentlicht 09.09.2017 01:29:02
- Zuletzt bearbeitet 20.04.2025 01:37:25
In libavformat/asfdec_f.c in FFmpeg 3.3.3, a DoS in asf_build_simple_index() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted ASF file, which claims a large "ict" field in the header but does not contain suff...
CVE-2017-14167
- EPSS 0.15%
- Veröffentlicht 08.09.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the load_multiboot function in hw/i386/multiboot.c in QEMU (aka Quick Emulator) allows local guest OS users to execute arbitrary code on the host via crafted multiboot header address values, which trigger an out-of-bounds write.
CVE-2017-6362
- EPSS 2.14%
- Veröffentlicht 07.09.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
CVE-2017-14169
- EPSS 0.24%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, which claims a large "item_num" field such as 0xffffffff, is provided. As a result, the variable "item_n...
CVE-2017-14172
- EPSS 0.58%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" field in the header but does not contain sufficient b...
CVE-2017-14173
- EPSS 1.4%
- Veröffentlicht 07.09.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smaller value than expected. As a result, an infinite loo...