Show filters
111 Total Results
Displaying 31-40 of 111
Sort by:
Attacker Value
Unknown

CVE-2017-17782

Disclosure Date: December 20, 2017 (last updated November 08, 2023)
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.
0
Attacker Value
Unknown

CVE-2017-17783

Disclosure Date: December 20, 2017 (last updated November 08, 2023)
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
0
Attacker Value
Unknown

CVE-2017-17500

Disclosure Date: December 11, 2017 (last updated November 08, 2023)
ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.
0
Attacker Value
Unknown

CVE-2017-17503

Disclosure Date: December 11, 2017 (last updated November 08, 2023)
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.
0
Attacker Value
Unknown

CVE-2017-17501

Disclosure Date: December 11, 2017 (last updated November 08, 2023)
WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.
0
Attacker Value
Unknown

CVE-2017-17502

Disclosure Date: December 11, 2017 (last updated November 08, 2023)
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.
0
Attacker Value
Unknown

CVE-2017-8028

Disclosure Date: November 27, 2017 (last updated November 26, 2024)
In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs because some LDAP vendors require an explicit operation for the LDAP bind to take effect.
0
Attacker Value
Unknown

CVE-2017-2919

Disclosure Date: November 20, 2017 (last updated November 26, 2024)
An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability
Attacker Value
Unknown

CVE-2017-16651

Disclosure Date: November 09, 2017 (last updated November 26, 2024)
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to authenticate at the target system with a valid username/password as the attack requires an active session. The issue is related to file-based attachment plugins and _task=settings&_action=upload-display&_from=timezone requests.
Attacker Value
Unknown

CVE-2017-16669

Disclosure Date: November 09, 2017 (last updated November 26, 2024)
coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.
0