|
199721
|
7.5 |
HIGH
Network
|
libsass
|
libsass
|
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11341
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199722
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote denial of service attack.
|
CWE-20
Improper Input Validation
|
CVE-2017-11340
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199723
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is a heap-based buffer overflow in the Image::printIFDStructure function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11339
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199724
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-11338
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199725
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack.
|
CWE-416
Use After Free
|
CVE-2017-11337
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199726
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-11336
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199727
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
There is a heap based buffer overflow in tools/tiff2pdf.c of LibTIFF 4.0.8 via a PlanarConfig=Contig image, which causes a more than one hundred bytes out-of-bounds write (related to the ZIPDecode fu…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-11335
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199728
|
9.8 |
CRITICAL
Network
|
glpi-project
|
glpi
|
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.
|
CWE-89
SQL Injection
|
CVE-2017-11329
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199729
|
5.5 |
MEDIUM
Local
|
virustotal
|
yara
|
Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11328
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199730
|
8.1 |
HIGH
Network
|
cobiansoft
|
cobian_backup
|
Cobian Backup 11 client allows man-in-the-middle attackers to add and execute new backup tasks when the master server is spoofed. In addition, the attacker can execute system commands remotely by abu…
|
CWE-78
OS Command
|
CVE-2017-11318
|
2024-11-21 12:07 |
2017-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|