Unknown · CVSS Not scored
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and have Internet access. This device acts as a Wireless Blood pressure monitor and is used to measure blood pressure levels of a person. This allows an attacker who is in vicinity of Wireless signal generated by the Blipcare device to easily sniff the credentials. Also, an attacker can connect to the open wireless network "Blip" exposed by the device and modify the HTTP response presented to the user by the device to execute other attacks such as convincing the user to download and execute a malicious binary that would infect a user's computer or mobile device with malware.
Published Jul 2, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a call from the readttfcopyrights function in parsettf.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Blipcare Wifi blood pressure monitor BP700 10.1 devices allow memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection provided by the device, if a large string is sent as a part of the HTTP request in any part of the HTTP headers, the device could become completely unresponsive. Presumably this happens as the memory footprint provided to this device is very small. According to the specs from Rezolt, the Wi-Fi module only has 256k of memory. As a result, an incorrect string copy operation using either memcpy, strcpy, or any of their other variants could result in filling up the memory space allocated to the function executing and this would result in memory corruption. To test the theory, one can modify the demo application provided by the Cypress WICED SDK and introduce an incorrect "memcpy" operation and use the compiled application on the evaluation board provided by Cypress semiconductors with exactly the same Wi-Fi SOC. The results were identical where the device would completely stop responding to any of the ping or web requests.
Published Jul 2, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to an address access exception in the WritePTIFImage() function in coders/tiff.c.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
It was discovered as a part of the research on IoT devices in the most recent firmware for Blipcare device that the device allows to connect to web management interface on a non-SSL connection using plain text HTTP protocol. The user uses the web management interface of the device to provide the user's Wi-Fi credentials so that the device can connect to it and have Internet access. This device acts as a Wireless Blood pressure monitor and is used to measure blood pressure levels of a person. This allows an attacker who is connected to the Blipcare's device wireless network to easily sniff these values using a MITM attack.
Published Jul 2, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. During the TIFFOpen process, td_imagelength is not checked. The value of td_imagelength can be directly controlled by an input file. In the ChopUpSingleUncompressedStrip function, the _TIFFCheckMalloc function is called based on td_imagelength. If we set the value of td_imagelength close to the amount of system memory, it will hang the system or trigger the OOM killer.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishandled. A remote attacker could potentially use this flaw to crash the sipdump process by generating specially crafted SIP traffic.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FontForge 20161012 does not ensure a positive size in a weight vector memcpy call in readcfftopdict (parsettf.c) resulting in DoS via a crafted otf file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
AppUse 4.0 allows shell command injection via a proxy field.
Published Jul 25, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafted otf file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy_id is XFRM_POLICY_MAX or less, which allows local users to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via an XFRM_MSG_MIGRATE xfrm Netlink message.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
dayrui FineCms through 5.0.10 has Cross Site Scripting (XSS) in controllers/api.php via the function parameter in a c=api&m=data2 request.
Published Jul 26, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is remote command execution via shell metacharacters in the pingAddr parameter to the waitPingqry.cgi URI. The command output is visible at /PingMsg.cmd.
Published Jul 24, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The play_midi function in playmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mid file. NOTE: CPU consumption might be relevant when using the --background option.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted otf file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
debian/tor.init in the Debian tor_0.2.9.11-1~deb9u1 package for Tor was designed to execute aa-exec from the standard system pathname if the apparmor package is installed, but implements this incorrectly (with a wrong assumption that the specific pathname would remain the same forever), which allows attackers to bypass intended AppArmor restrictions by leveraging the silent loss of this protection mechanism. NOTE: this does not affect systems, such as default Debian stretch installations, on which Tor startup relies on a systemd unit file (instead of this tor.init script).
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The id3_ucs4_length function in ucs4.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteOnePNGImage() function in coders/png.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Node.js v4.0 through v4.8.3, all versions of v5.x, v6.0 through v6.11.0, v7.0 through v7.10.0, and v8.0 through v8.1.3 was susceptible to hash flooding remote DoS attacks as the HashTable seed was constant across a given released version of Node.js. This was a result of building with V8 snapshots enabled by default which caused the initially randomized seed to be overwritten on startup.
Published Jul 25, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of service.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a stack consumption vulnerability in the Parser::advanceToNextToken function in parser.cpp in LibSass 3.4.5. A crafted input may lead to remote denial of service.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a stack consumption vulnerability in the lex function in parser.hpp (as used in sassc) in LibSass 3.4.5. A crafted input will lead to a remote denial of service.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uil.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the ReadOnePNGImage() function in coders/png.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
Published Jul 20, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The resample_gauss function in resample.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mid file. NOTE: a crash might be relevant when using the --background option. NOTE: the TiMidity++ README.alsaseq documentation suggests a setuid-root installation.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of service (memory corruption) via a crafted MP3 file.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The insert_note_steps function in readmidi.c in TiMidity++ 2.14.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mid file. NOTE: a crash might be relevant when using the --background option.
Published Jul 31, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadDPXImage function in coders/dpx.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadOneJNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a malformed JNG file.
Published Jul 21, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteJP2Image() function in coders/jp2.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteHISTOGRAMImage() function in coders/histogram.c.
Published Jul 23, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The ReadMATImage function in coders/mat.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
Published Jul 23, 2017 · Updated Aug 5, 2024