Show filters
733 Total Results
Displaying 471-480 of 733
Sort by:
Attacker Value
Unknown

CVE-2017-13065

Disclosure Date: August 22, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.
0
Attacker Value
Unknown

CVE-2017-13063

Disclosure Date: August 22, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
0
Attacker Value
Unknown

CVE-2017-13064

Disclosure Date: August 22, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
0
Attacker Value
Unknown

CVE-2017-13066

Disclosure Date: August 22, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.
0
Attacker Value
Unknown

CVE-2017-12935

Disclosure Date: August 18, 2017 (last updated November 08, 2023)
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
0
Attacker Value
Unknown

CVE-2017-12936

Disclosure Date: August 18, 2017 (last updated November 08, 2023)
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
0
Attacker Value
Unknown

CVE-2017-12937

Disclosure Date: August 18, 2017 (last updated November 08, 2023)
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
0
Attacker Value
Unknown

CVE-2017-9857

Disclosure Date: August 05, 2017 (last updated November 08, 2023)
An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. Any setting change, authentication packet, scouting packet, etc. can be replayed, injected, or used for a man in the middle session. All functionalities available in Sunny Explorer can effectively be done from anywhere within the network as long as an attacker gets the packet setup correctly. This includes the authentication process for all (including hidden) access levels and the changing of settings in accordance with the gained access rights. Furthermore, because the SMAdata2+ communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower…
0
Attacker Value
Unknown

CVE-2017-9860

Disclosure Date: August 05, 2017 (last updated November 08, 2023)
An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an attacker is able to create a custom firmware version that is accepted by the inverter, the inverter is compromised completely. This allows the attacker to do nearly anything: for example, giving access to the local OS, creating a botnet, using the inverters as a stepping stone into companies, etc. NOTE: the vendor reports that this attack has always been blocked by "a final integrity and compatibility check." Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
0
Attacker Value
Unknown

CVE-2017-9851

Disclosure Date: August 05, 2017 (last updated November 08, 2023)
An issue was discovered in SMA Solar Technology products. By sending nonsense data or setting up a TELNET session to the database port of Sunny Explorer, the application can be crashed. NOTE: the vendor reports that the maximum possible damage is a communication failure. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
0