Total
11965 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-10924 | 1 Irfanview | 2 Fpx, Irfanview | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
IrfanView 4.44 (32bit) with FPX Plugin 4.47 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "User Mode Write AV starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000a529." | |||||
CVE-2017-10925 | 1 Irfanview | 2 Fpx, Irfanview | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
IrfanView 4.44 (32bit) with FPX Plugin 4.47 might allow attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at FPX!FPX_GetScanDevicePropertyGroup+0x000000000000b3ae." | |||||
CVE-2017-9433 | 1 Libmwaw Project | 1 Libmwaw | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
Document Liberation Project libmwaw before 2017-04-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the MsWrd1Parser::readFootnoteCorrespondance function in lib/MsWrd1Parser.cxx. | |||||
CVE-2017-14693 | 1 Irfanview | 1 Irfanview | 2017-11-04 | 4.6 MEDIUM | 7.8 HIGH |
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613." | |||||
CVE-2016-7996 | 1 Graphicsmagick | 1 Graphicsmagick | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries. | |||||
CVE-2016-10326 | 1 Gnu | 1 Osip | 2017-11-04 | 5.0 MEDIUM | 7.5 HIGH |
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. | |||||
CVE-2015-8472 | 2 Apple, Libpng | 2 Mac Os X, Libpng | 2017-11-04 | 7.5 HIGH | 7.3 HIGH |
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8126. | |||||
CVE-2017-8366 | 1 Ettercap Project | 1 Ettercap | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted filter that is mishandled by etterfilter. | |||||
CVE-2016-10324 | 1 Gnu | 1 Osip | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. | |||||
CVE-2017-5225 | 1 Libtiff | 1 Libtiff | 2017-11-04 | 7.5 HIGH | 9.8 CRITICAL |
LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value. | |||||
CVE-2017-6830 | 1 Audiofile | 1 Audiofile | 2017-11-04 | 4.3 MEDIUM | 5.5 MEDIUM |
Heap-based buffer overflow in the alaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file. | |||||
CVE-2017-6887 | 1 Libraw | 1 Libraw | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to cause a memory corruption via e.g. a specially crafted KDC file with model set to "DSLR-A100" and containing multiple sequences of 0x100 and 0x14A TAGs. | |||||
CVE-2016-10325 | 1 Gnu | 1 Osip | 2017-11-04 | 5.0 MEDIUM | 7.5 HIGH |
In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. | |||||
CVE-2015-8808 | 3 Fedoraproject, Graphicsmagick, Suse | 5 Fedora, Graphicsmagick, Linux Enterprise Debuginfo and 2 more | 2017-11-04 | 4.3 MEDIUM | 5.5 MEDIUM |
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file. | |||||
CVE-2017-14578 | 1 Irfanview | 1 Irfanview | 2017-11-04 | 4.6 MEDIUM | 7.8 HIGH |
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .ani file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77130000!RtlpCoalesceFreeBlocks+0x00000000000004b4." | |||||
CVE-2017-10971 | 1 X.org | 1 Xorg-server | 2017-11-04 | 6.5 MEDIUM | 8.8 HIGH |
In the X.Org X server before 2017-06-19, a user authenticated to an X Session could crash or execute code in the context of the X Server by exploiting a stack overflow in the endianness conversion of X Events. | |||||
CVE-2016-4302 | 2 Libarchive, Redhat | 8 Libarchive, Enterprise Linux Desktop, Enterprise Linux Hpc Node and 5 more | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. | |||||
CVE-2017-6827 | 1 Audiofile | 1 Audiofile | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file. | |||||
CVE-2017-14539 | 1 Irfanview | 1 Irfanview | 2017-11-04 | 4.6 MEDIUM | 7.8 HIGH |
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at image00000000_00400000+0x000000000011d767." | |||||
CVE-2017-6828 | 1 Audiofile | 1 Audiofile | 2017-11-04 | 6.8 MEDIUM | 7.8 HIGH |
Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file. |