|
197611
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have un…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14333
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197612
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14326
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197613
|
7.5 |
HIGH
Adjacent
|
apple
|
iphone_os
|
In Apple iOS 7 through 9, due to a BlueBorne flaw in the implementation of LEAP (Low Energy Audio Protocol), a large audio command can be sent to a targeted device and lead to a heap overflow with at…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14315
|
2024-11-21 12:12 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197614
|
7.5 |
HIGH
Network
|
hbgk
|
hb7024xt_firmware hb7032xt_firmware hb7008t2_firmware hb7016t2_firmware hb7204xt_firmware hb7208xt_firmware hb7216xt_firmware hb7208x3_firmware hb7216x3_firmware hb7204x_fi…
|
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.
|
CWE-20
Improper Input Validation
|
CVE-2017-14335
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197615
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadM…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14325
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197616
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-14324
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197617
|
7.8 |
HIGH
Local
|
broadcom
|
tcpreplay
|
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14266
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197618
|
6.5 |
MEDIUM
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDashPolygon heap-based buffer over-read and applicatio…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14314
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197619
|
6.1 |
MEDIUM
Network
|
shibboleth_project
|
shibboleth
|
The shibboleth_login_form function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of add_query_arg().
|
CWE-79
Cross-site Scripting
|
CVE-2017-14313
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197620
|
7.8 |
HIGH
Local
|
nagios
|
nagios_core
|
Nagios Core through 4.3.4 initially executes /usr/sbin/nagios as root but supports configuration options in which this file is owned by a non-root account (and similarly can have nagios.cfg owned by …
|
CWE-269
Improper Privilege Management
|
CVE-2017-14312
|
2024-11-21 12:12 |
2017-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|