CVE-2017-12629
- EPSS 93.89%
- Veröffentlicht 14.10.2017 23:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-listener command to reach the RunExecutableListener class. Elasticsearch, although it uses Lucene, is N...
CVE-2017-15298
- EPSS 0.45%
- Veröffentlicht 14.10.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an impact of disk consumption; however, an affected pro...
CVE-2017-15281
- EPSS 0.59%
- Veröffentlicht 12.10.2017 08:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised v...
CVE-2017-2888
- EPSS 2.8%
- Veröffentlicht 11.10.2017 18:29:05
- Zuletzt bearbeitet 20.04.2025 01:37:25
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocated which can lead to a buffer overflow and potential...
CVE-2017-0903
- EPSS 4.62%
- Veröffentlicht 11.10.2017 18:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalat...
CVE-2017-15217
- EPSS 0.53%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
CVE-2017-15218
- EPSS 0.47%
- Veröffentlicht 10.10.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
CVE-2014-9092
- EPSS 1.87%
- Veröffentlicht 10.10.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
CVE-2017-15032
- EPSS 0.32%
- Veröffentlicht 05.10.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
CVE-2017-15033
- EPSS 0.26%
- Veröffentlicht 05.10.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.