Show filters
111 Total Results
Displaying 41-50 of 111
Sort by:
Attacker Value
Unknown

CVE-2017-16516

Disclosure Date: November 03, 2017 (last updated November 26, 2024)
In the yajl-ruby gem 1.3.0 for Ruby, when a crafted JSON file is supplied to Yajl::Parser.new.parse, the whole ruby process crashes with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This results in the whole ruby process terminating and potentially a denial of service.
Attacker Value
Unknown

CVE-2017-16352

Disclosure Date: November 01, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the DescribeImage() function of the magick/describe.c file. One possible way to trigger the vulnerability is to run the identify command on a specially crafted MIFF format file with the verbose flag.
0
Attacker Value
Unknown

CVE-2017-16353

Disclosure Date: November 01, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.
0
Attacker Value
Unknown

CVE-2017-15930

Disclosure Date: October 27, 2017 (last updated November 08, 2023)
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.
0
Attacker Value
Unknown

CVE-2017-15924

Disclosure Date: October 27, 2017 (last updated November 26, 2024)
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
0
Attacker Value
Unknown

CVE-2017-15238

Disclosure Date: October 11, 2017 (last updated November 08, 2023)
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
0
Attacker Value
Unknown

CVE-2017-14997

Disclosure Date: October 04, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
0
Attacker Value
Unknown

CVE-2017-14994

Disclosure Date: October 04, 2017 (last updated November 08, 2023)
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.
0
Attacker Value
Unknown

CVE-2017-14733

Disclosure Date: September 25, 2017 (last updated November 08, 2023)
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
0
Attacker Value
Unknown

CVE-2017-14160

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact via a crafted mp4 file.