CVE-2017-12836
- EPSS 4.28%
- Veröffentlicht 24.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."
CVE-2017-12809
- EPSS 0.09%
- Veröffentlicht 23.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty CDROM device drive.
- EPSS 93.79%
- Veröffentlicht 23.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace looku...
CVE-2017-12904
- EPSS 3.57%
- Veröffentlicht 23.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its t...
CVE-2017-13139
- EPSS 1.09%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
CVE-2017-13145
- EPSS 1.33%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
CVE-2017-5208
- EPSS 1.65%
- Veröffentlicht 22.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of executi...
CVE-2017-13063
- EPSS 1.54%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
CVE-2017-13064
- EPSS 1.7%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
CVE-2017-13065
- EPSS 1.29%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.