Search

Found 1,546 results in 215ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-13088 medium 5.3 5.3 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response fra…
CVE-2017-13087 medium 5.3 5.3 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowin…
CVE-2017-13086 medium 6.8 6.8 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decry…
CVE-2017-13084 medium 6.8 6.8 arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, …
CVE-2017-13082 high 8.1 8.1 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing …
CVE-2017-13081 medium 5.3 5.3 FIX arch arch slesdebian debian w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio ran…
CVE-2017-13080 medium 5.3 5.3 FIX arch arch slesdebian debian w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points…
CVE-2017-13079 medium 5.3 5.3 FIX arch arch slesdebian debian w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio rang…
CVE-2017-13078 medium 5.3 5.3 FIX arch arch slesdebian debian w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points …
CVE-2017-13077 medium 6.8 6.8 FIX arch arch slesdebian debian w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, dec…
CVE-2017-12629 critical 9.8 10.0 EXPFIX debian debianubuntu ubuntu rhel apacheredhat 9y ago Remote code execution occurs in Apache Solr
CVE-2017-15298 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu git-scm 9y ago Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory consumption) via a crafted repository, aka a Git bomb. This can also have an i…
CVE-2017-15281 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "…
CVE-2017-2888 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu libsdl 9y ago An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5. A specially crafted file can cause an integer overflow resulting in too little memory being allocate…
CVE-2017-15218 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
CVE-2017-15217 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
CVE-2014-9092 medium 6.5 6.5 FIX debian debianubuntu ubuntufedora fedora libjpeg-turbo 9y ago libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
CVE-2017-0903 critical 9.8 9.8 FIX slesubuntu ubuntudebian debian rubygems 9y ago RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted…
CVE-2017-15033 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.
CVE-2017-15032 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
CVE-2017-15017 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadOneMNGImage in coders/png.c.
CVE-2017-15016 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.
CVE-2017-15015 high 8.8 8.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.
CVE-2017-14491 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleyssusenvidia 9y ago Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.
CVE-2017-14496 high 7.5 8.5 EXPFIX arch archdebian debianubuntu ubuntu thekelleys 9y ago Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service …
CVE-2017-14495 high 7.5 8.5 EXPFIX arch arch slesdebian debian thekelleys 9y ago Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involvi…
CVE-2017-14494 medium 5.9 6.9 EXPFIX arch arch slesdebian debian thekelleys 9y ago dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
CVE-2017-14493 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleys 9y ago Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.
CVE-2017-14492 critical 9.8 10.0 EXPFIX arch arch slesdebian debian thekelleys 9y ago Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.
CVE-2017-13704 high 7.5 7.5 FIX debian debianubuntu ubuntufedora fedora thekelleys 9y ago In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0x…
CVE-2017-14864 medium 5.5 5.5 FIX debian debianubuntu ubuntu exiv2 9y ago An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of servi…
CVE-2017-14862 medium 5.5 5.5 FIX debian debianubuntu ubuntu exiv2 9y ago An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial o…
CVE-2017-14859 medium 5.5 5.5 FIX debian debianubuntu ubuntu exiv2 9y ago An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to de…
CVE-2015-3643 high 7.8 8.8 EXP ubuntu ubuntu usb-creator_project 9y ago usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local…
CVE-2015-1336 high 7.8 8.8 EXPFIX debian debianubuntu ubuntu man-db_project 9y ago The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access to the man account to gain privileges via vectors involving insecure chown use.
CVE-2017-12153 medium 4.4 4.4 FIX slesdebian debian linux-kernel 9y ago A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are …
CVE-2017-14633 medium 6.5 6.5 FIX arch arch slesdebian debian xiph.org 9y ago In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbi…
CVE-2017-14632 critical 9.8 9.8 FIX arch arch slesdebian debian xiph.org 9y ago Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 5501…
CVE-2017-14626 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.
CVE-2017-14625 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.
CVE-2017-14624 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c.
CVE-2017-14607 high 8.1 8.1 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploit this flaw to disclose potentially sensitive memo…
CVE-2015-1329 high 8.8 8.8 ubuntu ubuntu 9y ago Use-after-free vulnerability in oxide::qt::URLRequestDelegatedJob in oxide-qt in Ubuntu 15.04 and 14.04 LTS might allow remote attackers to execute arbitrary code.
CVE-2017-14533 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
CVE-2017-14532 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.
CVE-2017-14531 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-0 has a memory exhaustion issue in ReadSUNImage in coders/sun.c.
CVE-2017-14343 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.6-6 has a memory leak vulnerability in ReadXCFImage in coders/xcf.c via a crafted xcf image file.
CVE-2017-14342 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.6-6 has a memory exhaustion vulnerability in ReadWPGImage in coders/wpg.c via a crafted wpg image file.
CVE-2017-14341 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.6-6 has a large loop vulnerability in ReadWPGImage in coders/wpg.c, causing CPU exhaustion via a crafted wpg image file.
CVE-2017-14326 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-14325 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadM…
CVE-2017-14228 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.
CVE-2017-6362 high 7.5 7.5 FIX slesdebian debianfedora fedora libgd 9y ago Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
CVE-2017-14175 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and co…
CVE-2017-14174 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large …
CVE-2017-14173 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smalle…
CVE-2017-14172 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" fi…
CVE-2017-14166 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchive 9y ago RHEA-2021:1580: libarchive bug fix and enhancement update (Moderate)
CVE-2017-12693 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted BMP file.
CVE-2017-12692 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted VIFF file.
CVE-2017-12691 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CVE-2017-14064 critical 9.8 9.8 slesdebian debian rhel ruby-lang 9y ago Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
CVE-2017-14060 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixel…
CVE-2017-13769 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file.
CVE-2017-13768 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file.
CVE-2017-0902 high 8.1 8.1 FIX slesdebian debian rhel rubygems 9y ago RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacke…
CVE-2017-0901 high 7.5 8.5 EXPFIX slesdebian debian rhel rubygems 9y ago RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
CVE-2017-12877 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
CVE-2015-1395 high 7.5 7.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a…
CVE-2015-1325 high 7.0 8.0 EXP ubuntu ubuntu 9y ago Race condition in Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and befo…
CVE-2015-1324 high 7.8 7.8 ubuntu ubuntu 9y ago Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17…
CVE-2014-9637 medium 5.5 5.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
CVE-2017-12836 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand…
CVE-2017-13145 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
CVE-2017-13139 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
CVE-2016-6796 high 7.5 7.5 slesdebian debian rhel apachenetapporacle 9y ago Apache Tomcat vulnerable to SecurityManager bypass
CVE-2016-6797 high 7.5 7.5 slesdebian debian rhel apacheoraclenetapp 9y ago Incorrect Authorization in Apache Tomcat
CVE-2016-6794 medium 5.3 5.3 slesdebian debian rhel apacheredhatnetapp 9y ago System Property Disclosure in Apache Tomcat
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2016-0762 medium 5.9 5.9 slesdebian debian rhel apacheredhatnetapp 9y ago Observable Discrepancy in Apache Tomcat
CVE-2017-12762 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux …
CVE-2011-5325 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu busybox 9y ago Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.
CVE-2017-11683 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVE-2015-1332 high 8.8 8.8 ubuntu ubuntu oxide_project 9y ago The oxide::JavaScriptDialogManager function in oxide-qt before 1.9.1 as packaged in Ubuntu 15.04 and Ubuntu 14.04 allows remote attackers to cause a denial of service (application crash) or execute a…
CVE-2017-7980 high 7.8 7.8 FIX sles rhelubuntu ubuntu qemuredhat 9y ago Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vec…
CVE-2017-11591 high 7.5 7.5 FIX slesarch archdebian debian exiv2 9y ago There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVE-2015-5300 high 7.5 7.5 FIX rhelubuntu ubuntufedora fedora susentp 9y ago The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to…
CVE-2015-5219 high 7.5 7.5 FIX rhelubuntu ubuntufedora fedora susentp 9y ago The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infin…
CVE-2015-5195 high 7.5 7.5 FIX slesdebian debian rhel ntp 9y ago ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled …
CVE-2015-5194 high 7.5 7.5 FIX slesdebian debian rhel susentp 9y ago The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
CVE-2015-1323 medium 5.5 5.5 ubuntu ubuntu 9y ago The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ub…
CVE-2017-11473 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table.
CVE-2017-11352 medium 6.5 6.5 FIX slesarch archdebian debian imagemagick 9y ago In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-91…
CVE-2017-1000050 high 7.5 7.5 slesubuntu ubuntu rhel jasper_project 9y ago JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
CVE-2017-11111 high 7.8 7.8 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, preproc.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a …
CVE-2017-10686 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The related heap is allocated in the token() function and freed in the detoken() function…
CVE-2017-9985 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary access) or possibly have unspecifi…
CVE-2015-5180 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
CVE-2017-9936 medium 6.5 7.5 EXPFIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9935 high 8.8 8.8 FIX arch arch slesdebian debian libtiff 9y ago In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can…