CVE-2012-1186
- EPSS 0.27%
- Veröffentlicht 05.06.2012 22:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exis...
CVE-2012-0248
- EPSS 0.29%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
CVE-2012-0259
- EPSS 1.43%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-b...
CVE-2012-0260
- EPSS 1.94%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
CVE-2012-0247
- EPSS 4.21%
- Veröffentlicht 05.06.2012 22:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
CVE-2012-2947
- EPSS 4.3%
- Veröffentlicht 02.06.2012 15:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting is enabled, allows remote attackers to cause a den...
- EPSS 0.49%
- Veröffentlicht 29.05.2012 20:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute ar...
CVE-2012-0879
- EPSS 0.05%
- Veröffentlicht 17.05.2012 11:00:36
- Zuletzt bearbeitet 29.04.2026 01:13:23
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context...
CVE-2012-1823
- EPSS 94.36%
- Veröffentlicht 11.05.2012 10:15:48
- Zuletzt bearbeitet 21.04.2026 20:28:53
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by ...
CVE-2012-0216
- EPSS 0.05%
- Veröffentlicht 22.04.2012 18:55:03
- Zuletzt bearbeitet 27.08.2025 11:17:02
The default configuration of the apache2 package in Debian GNU/Linux squeeze before 2.2.16-6+squeeze7, wheezy before 2.2.22-4, and sid before 2.2.22-4, when mod_php or mod_rivet is used, provides example scripts under the doc/ URI, which might allow ...