|
255441
|
7.5 |
HIGH
Network
|
wireshark
|
wireshark
|
In Wireshark 2.4.0, the Modbus dissector could crash with a NULL pointer dereference. This was addressed in epan/dissectors/packet-mbtcp.c by adding length validation.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-13764
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255442
|
7.5 |
HIGH
Network
|
onosproject
|
onos
|
ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-13763
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255443
|
6.1 |
MEDIUM
Network
|
onosproject
|
onos
|
ONOS versions 1.8.0, 1.9.0, and 1.10.0 are vulnerable to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-13762
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255444
|
5.5 |
MEDIUM
Local
|
sleuthkit debian
|
the_sleuth_kit debian_linux
|
In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13760
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255445
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-10, there is a heap-based buffer overflow in the TracePoint() function in MagickCore/draw.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-13758
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255446
|
5.5 |
MEDIUM
Local
|
gnu
|
binutils
|
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-ba…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-13757
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255447
|
5.5 |
MEDIUM
Local
|
sleuthkit debian
|
the_sleuth_kit debian_linux
|
In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as demonstrated by mmls.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-13756
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255448
|
5.5 |
MEDIUM
Local
|
sleuthkit debian
|
the_sleuth_kit debian_linux
|
In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libtskfs.a, as demonstrated by fls.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-13755
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255449
|
6.5 |
MEDIUM
Network
|
qemu
|
qemu
|
The vga display update in mis-calculated the region for the dirty bitmap snapshot in case split screen mode is used causing a denial of service (assertion failure) in the cpu_physical_memory_snapshot…
|
CWE-617
Reachable Assertion
|
CVE-2017-13673
|
2024-11-21 12:11 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255450
|
7.5 |
HIGH
Network
|
jasper_project fedoraproject
|
jasper fedora
|
There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
|
CWE-617
Reachable Assertion
|
CVE-2017-13752
|
2024-11-21 12:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|