CVE-2017-9935
- EPSS 0.55%
- Veröffentlicht 26.06.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an i...
CVE-2017-9936
- EPSS 6.04%
- Veröffentlicht 26.06.2017 12:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9928
- EPSS 0.42%
- Veröffentlicht 26.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9929
- EPSS 0.42%
- Veröffentlicht 26.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9868
- EPSS 0.11%
- Veröffentlicht 25.06.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
CVE-2017-9865
- EPSS 0.76%
- Veröffentlicht 25.06.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document, related to missing color-map validation in I...
CVE-2017-9775
- EPSS 0.78%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
CVE-2017-9776
- EPSS 1.25%
- Veröffentlicht 22.06.2017 21:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
CVE-2017-9780
- EPSS 0.04%
- Veröffentlicht 21.06.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example setuid or world-writable. The files are deployed with those permissions, which would let a local attacke...
CVE-2017-9766
- EPSS 0.89%
- Veröffentlicht 21.06.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Wireshark 2.2.7, PROFINET IO data with a high recursion depth allows remote attackers to cause a denial of service (stack exhaustion) in the dissect_IODWriteReq function in plugins/profinet/packet-dcerpc-pn-io.c.