CVE-2012-0948
- EPSS 0.05%
- Veröffentlicht 07.06.2012 21:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
DistUpgrade/DistUpgradeMain.py in Update Manager, as used by Ubuntu 12.04 LTS, 11.10, and 11.04, uses weak permissions for (1) apt-clone_system_state.tar.gz and (2) system_state.tar.gz, which allows local users to obtain repository credentials.
CVE-2012-1610
- EPSS 7.03%
- Veröffentlicht 05.06.2012 22:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-4 allows remote attackers to cause a denial of service (out-of-bounds read) via a large component count for certain EXIF tags in a JPEG image. NOTE: th...
CVE-2012-1185
- EPSS 1.29%
- Veröffentlicht 05.06.2012 22:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in (1) magick/profile.c or (2) magick/property.c in ImageMagick 6.7.5 and earlier allow remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset value in the R...
CVE-2012-1186
- EPSS 0.27%
- Veröffentlicht 05.06.2012 22:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the SyncImageProfiles function in profile.c in ImageMagick 6.7.5-8 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted IOP tag offsets in the IFD in an image. NOTE: this vulnerability exis...
CVE-2012-0248
- EPSS 0.29%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
CVE-2012-0259
- EPSS 1.43%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a zero value in the component count of an EXIF XResolution tag in a JPEG file, which triggers an out-of-b...
CVE-2012-0260
- EPSS 1.94%
- Veröffentlicht 05.06.2012 22:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
CVE-2012-0247
- EPSS 4.21%
- Veröffentlicht 05.06.2012 22:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted offset and count values in the ResolutionUnit tag in the EXIF IFD0 of an image.
CVE-2012-0944
- EPSS 0.48%
- Veröffentlicht 04.06.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Aptdaemon 0.43 and earlier in Ubuntu 11.04, 11.10, and 12.04 LTS does not authenticate packages when the transaction is not simulated, which allows remote attackers to install arbitrary packages via a man-in-the-middle attack.
- EPSS 0.47%
- Veröffentlicht 31.05.2012 17:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Apport hook in Update Manager as used by Ubuntu 12.04 LTS, 11.10, and 11.04 uploads certain system state archive files when reporting bugs to Launchpad, which allows remote attackers to read repository credentials by viewing a public bug report.