Show filters
230 Total Results
Displaying 201-210 of 230
Sort by:
Attacker Value
Unknown

CVE-2017-6196

Disclosure Date: February 24, 2017 (last updated November 08, 2023)
Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.
0
Attacker Value
Unknown

CVE-2016-8674

Disclosure Date: February 15, 2017 (last updated November 08, 2023)
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
0
Attacker Value
Unknown

CVE-2017-5896

Disclosure Date: February 15, 2017 (last updated November 08, 2023)
Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image.
0
Attacker Value
Unknown

CVE-2017-5991

Disclosure Date: February 15, 2017 (last updated November 08, 2023)
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
Attacker Value
Unknown

CVE-2016-9108

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
Attacker Value
Unknown

CVE-2017-5627

Disclosure Date: January 30, 2017 (last updated November 08, 2023)
An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks a check for a negative array length. This leads to an integer overflow in the js_pushstring function in jsrun.c when parsing a specially crafted JS file.
Attacker Value
Unknown

CVE-2017-5628

Disclosure Date: January 30, 2017 (last updated November 08, 2023)
An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not validate the month, leading to an integer overflow when parsing a specially crafted JS file.
Attacker Value
Unknown

CVE-2016-9109

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerability exists due to an incomplete fix for CVE-2016-7563.
0
Attacker Value
Unknown

CVE-2016-7563

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.
0
Attacker Value
Unknown

CVE-2016-7564

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of service (crash) via crafted input.
0