|
249191
|
6.5 |
MEDIUM
Network
|
imagemagick debian canonical
|
imagemagick debian_linux ubuntu_linux
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhausti…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18273
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249192
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is m…
|
CWE-416
Use After Free
|
CVE-2017-18272
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249193
|
6.5 |
MEDIUM
Network
|
imagemagick canonical debian
|
imagemagick ubuntu_linux debian_linux
|
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaus…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18271
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249194
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel before 4.13.5, a local user could create keyrings for other users via keyctl commands, setting unwanted defaults or causing a denial of service.
|
NVD-CWE-noinfo
|
CVE-2017-18270
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249195
|
9.8 |
CRITICAL
Network
|
gnu
|
glibc
|
An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the ove…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18269
|
2024-11-21 12:19 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249196
|
5.9 |
MEDIUM
Network
|
broadcom
|
symantec_intelligencecenter
|
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat (ROBOT) attack. A remote attacker, who has captured a pre-recorded SSL session inspected by SSLV, can e…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2017-18268
|
2024-11-21 12:19 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249197
|
5.5 |
MEDIUM
Local
|
freedesktop canonical redhat debian
|
poppler ubuntu_linux ansible_tower enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux
|
The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by …
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-18267
|
2024-11-21 12:19 |
2018-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249198
|
8.8 |
HIGH
Network
|
freedesktop debian canonical
|
xdg-utils debian_linux ubuntu_linux
|
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers…
|
CWE-74
Injection
|
CVE-2017-18266
|
2024-11-21 12:19 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249199
|
7.5 |
HIGH
Network
|
prosody debian
|
prosody debian_linux
|
Prosody before 0.10.0 allows remote attackers to cause a denial of service (application crash), related to an incompatibility with certain versions of the LuaSocket library, such as the lua-socket pa…
|
NVD-CWE-noinfo
|
CVE-2017-18265
|
2024-11-21 12:19 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249200
|
9.8 |
CRITICAL
Network
|
phpmyadmin debian
|
phpmyadmin debian_linux
|
An issue was discovered in libraries/common.inc.php in phpMyAdmin 4.0 before 4.0.10.20, 4.4.x, 4.6.x, and 4.7.0 prereleases. The restrictions caused by $cfg['Servers'][$i]['AllowNoPassword'] = false …
|
NVD-CWE-noinfo
|
CVE-2017-18264
|
2024-11-21 12:19 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|