Show filters
34 Total Results
Displaying 21-30 of 34
Sort by:
Attacker Value
Unknown

CVE-2018-7440

Disclosure Date: February 23, 2018 (last updated December 19, 2023)
An issue was discovered in Leptonica through 1.75.3. The gplotMakeOutput function allows command injection via a $(command) approach in the gplot rootname argument. This issue exists because of an incomplete fix for CVE-2018-3836.
0
Attacker Value
Unknown

CVE-2018-7247

Disclosure Date: February 19, 2018 (last updated December 19, 2023)
An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact.
0
Attacker Value
Unknown

CVE-2018-7186

Disclosure Date: February 16, 2018 (last updated December 19, 2023)
Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions.
0
Attacker Value
Unknown

CVE-2017-8891

Disclosure Date: May 10, 2017 (last updated November 26, 2024)
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
0
Attacker Value
Unknown

CVE-2017-7448

Disclosure Date: April 05, 2017 (last updated November 26, 2024)
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.
0
Attacker Value
Unknown

CVE-2016-6237

Disclosure Date: February 02, 2017 (last updated November 25, 2024)
The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.
0
Attacker Value
Unknown

CVE-2016-6234

Disclosure Date: February 02, 2017 (last updated November 25, 2024)
The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.
0
Attacker Value
Unknown

CVE-2016-6235

Disclosure Date: February 02, 2017 (last updated November 25, 2024)
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file.
0
Attacker Value
Unknown

CVE-2016-6236

Disclosure Date: February 02, 2017 (last updated November 25, 2024)
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.
0
Attacker Value
Unknown

CVE-2016-6238

Disclosure Date: February 02, 2017 (last updated November 25, 2024)
The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file.
0