|
198401
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-11338
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198402
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
|
CWE-416
Use After Free
|
CVE-2017-11337
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198403
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11336
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198404
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode fu…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-11335
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198405
|
9.8 |
CRITICAL
Network
|
glpi-project
|
glpi
|
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
|
CWE-89
SQL Injection
|
CVE-2017-11329
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198406
|
5.5 |
MEDIUM
Local
|
virustotal
|
yara
|
Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11328
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198407
|
8.1 |
HIGH
Network
|
cobiansoft
|
cobian_backup
|
Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abu…
|
CWE-78
OS Command
|
CVE-2017-11318
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198408
|
7.8 |
HIGH
Local
|
openmpt
|
libopenmpt openmpt
|
soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that trigge…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11311
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198409
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-11310
|
2024-11-21 12:07 |
2017-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198410
|
8.1 |
HIGH
Network
|
heimdal_project freebsd samba apple debian
|
heimdal freebsd samba mac_os_x iphone_os debian_linux
|
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-11103
|
2024-11-21 12:07 |
2017-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|