|
247071
|
6.5 |
MEDIUM
Network
|
libtiff
|
libtiff
|
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-9147
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247072
|
8.8 |
HIGH
Network
|
ytnef_project
|
ytnef
|
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9146
|
2024-11-21 12:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247073
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
|
CWE-20
Improper Input Validation
|
CVE-2017-9144
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247074
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick 7.0.5-5, the ReadARTImage function in coders/art.c allows attackers to cause a denial of service (memory leak) via a crafted .art file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-9143
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247075
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.
|
CWE-20 CWE-617
Improper Input Validation Reachable Assertion
|
CVE-2017-9142
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247076
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function …
|
CWE-20 CWE-617
Improper Input Validation Reachable Assertion
|
CVE-2017-9141
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247077
|
6.1 |
MEDIUM
Network
|
progress
|
telerik_reporting sitefinity_cms
|
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2017-9140
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247078
|
3.5 |
LOW
Adjacent
|
tendacn
|
f1200_firmware fh1202_firmware f1202_firmware
|
There is a stack-based buffer overflow on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). Crafted POST requests to an unspecified URL result in DoS, interrupting the HTTP service (…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9139
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247079
|
8.0 |
HIGH
Adjacent
|
tendacn
|
f1200_firmware fh1202_firmware f1202_firmware
|
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass inten…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-9138
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247080
|
8.8 |
HIGH
Network
|
mimosa
|
client_radios backhaul_radios
|
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are …
|
CWE-74
Injection
|
CVE-2017-9135
|
2024-11-21 12:35 |
2017-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|