|
252101
|
8.8 |
HIGH
Network
|
otrs
|
otrs
|
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code in…
|
CWE-20
Improper Input Validation
|
CVE-2017-14635
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252102
|
6.5 |
MEDIUM
Network
|
libsndfile_project debian
|
libsndfile debian_linux
|
In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.
|
CWE-369
Divide By Zero
|
CVE-2017-14634
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252103
|
6.5 |
MEDIUM
Network
|
xiph.org debian canonical
|
libvorbis debian_linux ubuntu_linux
|
In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS when operating on a crafted audio file with vorbi…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-14633
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252104
|
9.8 |
CRITICAL
Network
|
xiph.org debian canonical
|
libvorbis debian_linux ubuntu_linux
|
Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi->channels<=0, a similar issue to Mozilla bug 5501…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14632
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252105
|
9.8 |
CRITICAL
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, the pcxLoadRaster function in in_pcx.cpp has an integer signedness error leading to a heap-based buffer overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14631
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252106
|
9.8 |
CRITICAL
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, an integer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp, leading to an invalid write operation.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14630
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252107
|
7.5 |
HIGH
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, the in_xpm_reader function in in_xpm.cpp has an integer signedness error, leading to a crash when writing to an out-of-bounds array element.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14629
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252108
|
9.8 |
CRITICAL
Network
|
sam2p_project
|
sam2p
|
In sam2p 0.49.3, a heap-based buffer overflow exists in the pcxLoadImage24 function of the file in_pcx.cpp.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14628
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252109
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14626
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252110
|
9.8 |
CRITICAL
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-14625
|
2024-11-21 12:13 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|