Total
4813 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-9038 | 1 Gnu | 1 Binutils | 2017-09-18 | 4.3 MEDIUM | 5.5 MEDIUM |
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets. | |||||
CVE-2012-5109 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression. | |||||
CVE-2012-5110 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |||||
CVE-2017-14407 | 1 Mp3gain | 1 Mp3gain | 2017-09-18 | 4.3 MEDIUM | 5.5 MEDIUM |
A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service. | |||||
CVE-2017-14408 | 1 Mp3gain | 1 Mp3gain | 2017-09-18 | 4.3 MEDIUM | 5.5 MEDIUM |
A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service. | |||||
CVE-2017-14410 | 1 Mp3gain | 1 Mp3gain | 2017-09-18 | 4.3 MEDIUM | 5.5 MEDIUM |
A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial of service. | |||||
CVE-2017-12954 | 1 Libgig0 | 1 Libgig | 2017-09-05 | 4.3 MEDIUM | 6.5 MEDIUM |
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted gig file. | |||||
CVE-2016-3620 | 1 Libtiff | 1 Libtiff | 2017-09-02 | 5.0 MEDIUM | 7.5 HIGH |
The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image. | |||||
CVE-2016-3619 | 1 Libtiff | 1 Libtiff | 2017-09-02 | 4.3 MEDIUM | 6.5 MEDIUM |
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image. | |||||
CVE-2016-3621 | 1 Libtiff | 1 Libtiff | 2017-09-02 | 6.8 MEDIUM | 8.8 HIGH |
The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image. | |||||
CVE-2017-12958 | 1 Gnu | 1 Pspp | 2017-09-01 | 5.0 MEDIUM | 7.5 HIGH |
There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service. | |||||
CVE-2016-1513 | 1 Apache | 1 Openoffice | 2017-08-31 | 6.8 MEDIUM | 7.8 HIGH |
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted MetaActions in an (1) ODP or (2) OTP file. | |||||
CVE-2016-4628 | 1 Apple | 2 Iphone Os, Watchos | 2017-08-31 | 4.9 MEDIUM | 5.5 MEDIUM |
IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via unspecified vectors. | |||||
CVE-2016-4652 | 1 Apple | 1 Mac Os X | 2017-08-31 | 3.3 LOW | 6.3 MEDIUM |
CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a denial of service (out-of-bounds read), via unspecified vectors. | |||||
CVE-2015-9050 | 1 Google | 1 Android | 2017-08-24 | 10.0 HIGH | 9.8 CRITICAL |
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur during a CA call. | |||||
CVE-2017-12441 | 1 Minidjvu Project | 1 Minidjvu | 2017-08-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. | |||||
CVE-2017-12444 | 1 Minidjvu Project | 1 Minidjvu | 2017-08-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. | |||||
CVE-2017-12445 | 1 Minidjvu Project | 1 Minidjvu | 2017-08-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. | |||||
CVE-2017-12442 | 1 Minidjvu Project | 1 Minidjvu | 2017-08-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. | |||||
CVE-2017-12443 | 1 Minidjvu Project | 1 Minidjvu | 2017-08-22 | 4.3 MEDIUM | 6.5 MEDIUM |
The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. |