- EPSS 93.83%
- Veröffentlicht 23.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace looku...
CVE-2017-12904
- EPSS 3.14%
- Veröffentlicht 23.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its t...
CVE-2017-13139
- EPSS 1.15%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
CVE-2017-13145
- EPSS 1.33%
- Veröffentlicht 23.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
CVE-2017-5208
- EPSS 1.65%
- Veröffentlicht 22.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of executi...
CVE-2017-13063
- EPSS 1.54%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
CVE-2017-13064
- EPSS 1.7%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
CVE-2017-13065
- EPSS 1.29%
- Veröffentlicht 22.08.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
CVE-2017-10661
- EPSS 30%
- Veröffentlicht 19.08.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel q...
CVE-2017-12935
- EPSS 0.46%
- Veröffentlicht 18.08.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.