CVE-2017-9993
- EPSS 56.17%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist d...
CVE-2017-9994
- EPSS 0.42%
- Veröffentlicht 28.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow ...
CVE-2017-9935
- EPSS 0.63%
- Veröffentlicht 26.06.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an i...
CVE-2017-9936
- EPSS 6.04%
- Veröffentlicht 26.06.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9928
- EPSS 0.42%
- Veröffentlicht 26.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9929
- EPSS 0.42%
- Veröffentlicht 26.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9868
- EPSS 0.11%
- Veröffentlicht 25.06.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
CVE-2017-9865
- EPSS 0.76%
- Veröffentlicht 25.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in I...
CVE-2017-9775
- EPSS 0.78%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
CVE-2017-9776
- EPSS 1.25%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.