|
251881
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview pdf
|
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15242
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251882
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview pdf
|
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faul…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15241
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251883
|
7.8 |
HIGH
Local
|
irfanview
|
irfanview pdf
|
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Read Access …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15240
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251884
|
7.8 |
HIGH
Local
|
irfanview
|
pdf irfanview
|
IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Add…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15239
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251885
|
7.5 |
HIGH
Network
|
gnu
|
libextractor
|
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-15267
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251886
|
5.5 |
MEDIUM
Local
|
gnu
|
libextractor
|
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
|
CWE-369
Divide By Zero
|
CVE-2017-15266
|
2024-11-21 12:14 |
2017-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251887
|
9.8 |
CRITICAL
Network
|
flexense
|
vx_search
|
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginning with a /../ substring. This allows remote attackers to execute arbitrary cod…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-15220
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251888
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
|
CWE-416
Use After Free
|
CVE-2017-15238
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251889
|
7.5 |
HIGH
Network
|
tiandy
|
tiandy_ip_camera_firmware
|
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted request to TCP port 3001, as demonstrated by config…
|
CWE-200
Information Exposure
|
CVE-2017-15236
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251890
|
7.5 |
HIGH
Network
|
horde
|
groupware
|
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication for file downloads via a crafted fn parameter that corresponds to the exact fi…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2017-15235
|
2024-11-21 12:14 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|