|
248141
|
5.5 |
MEDIUM
Local
|
netpbm_project
|
netpbm
|
A memory allocation vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-2587
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248142
|
5.5 |
MEDIUM
Local
|
netpbm_project
|
netpbm
|
A null pointer dereference vulnerability was found in netpbm before 10.61. A maliciously crafted SVG file could cause the application to crash.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2586
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248143
|
7.8 |
HIGH
Local
|
netpbm_project
|
netpbm
|
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2581
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248144
|
7.8 |
HIGH
Local
|
netpbm_project
|
netpbm
|
An out-of-bounds write vulnerability was found in netpbm before 10.61. A maliciously crafted file could cause the application to crash or possibly allow code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-2580
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248145
|
7.8 |
HIGH
Local
|
netpbm_project
|
netpbm
|
An out-of-bounds read vulnerability was found in netpbm before 10.61. The expandCodeOntoStack() function has an insufficient code value check, so that a maliciously crafted file could cause the appli…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-2579
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248146
|
7.5 |
HIGH
Network
|
redhat debian
|
undertow debian_linux jboss_enterprise_application_platform
|
It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-2670
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248147
|
6.5 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform
|
It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.
|
CWE-22
Path Traversal
|
CVE-2017-2595
|
2024-11-21 12:23 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248148
|
7.5 |
HIGH
Network
|
redhat
|
cloudforms cloudforms_management_engine
|
It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communicating with Red Hat Virtualization (RHEV) and OpenSh…
|
-
|
CVE-2017-2639
|
2024-11-21 12:23 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248149
|
6.5 |
MEDIUM
Network
|
redhat debian
|
undertow jboss_enterprise_application_platform debian_linux
|
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid charac…
|
CWE-444
HTTP Request Smuggling
|
CVE-2017-2666
|
2024-11-21 12:23 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248150
|
5.5 |
MEDIUM
Local
|
redhat
|
openstack
|
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access…
|
-
|
CVE-2017-2622
|
2024-11-21 12:23 |
2018-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|