|
256151
|
9.8 |
CRITICAL
Network
|
ruby-lang
|
ruby
|
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-11465
|
2024-11-21 12:07 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256152
|
7.8 |
HIGH
Local
|
gnome
|
librsvg
|
A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero.
|
CWE-369
Divide By Zero
|
CVE-2017-11464
|
2024-11-21 12:07 |
2017-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256153
|
7.5 |
HIGH
Network
|
geneko
|
gwr352_3g_router_firmware gwr352wv_wide_voltage_3g_router_firmware gwr252_edge_router_firmware gwr202_gprs_router_firmware
|
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file.
|
CWE-22
Path Traversal
|
CVE-2017-11456
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256154
|
8.8 |
HIGH
Network
|
imagemagick debian
|
imagemagick debian_linux
|
coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via JPEG data that is too short.
|
NVD-CWE-noinfo
|
CVE-2017-11450
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256155
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
coders/mpc.c in ImageMagick before 7.0.6-1 does not enable seekable streams and thus cannot validate blob sizes, which allows remote attackers to cause a denial of service (application crash) or poss…
|
NVD-CWE-noinfo
|
CVE-2017-11449
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256156
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadJPEGImage function in coders/jpeg.c in ImageMagick before 7.0.6-1 allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted file.
|
CWE-200
Information Exposure
|
CVE-2017-11448
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256157
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadSCREENSHOTImage function in coders/screenshot.c in ImageMagick before 7.0.6-1 has memory leaks, causing denial of service.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-11447
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256158
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadPESImage function in coders\pes.c in ImageMagick 7.0.6-1 has an infinite loop vulnerability that can cause CPU exhaustion via a crafted PES file.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-11446
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256159
|
9.8 |
CRITICAL
Network
|
intelliants
|
subrion_cms
|
Subrion CMS before 4.1.6 has a SQL injection vulnerability in /front/actions.php via the $_POST array.
|
CWE-89
SQL Injection
|
CVE-2017-11445
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256160
|
9.8 |
CRITICAL
Network
|
intelliants
|
subrion_cms
|
Subrion CMS before 4.1.5.10 has a SQL injection vulnerability in /front/search.php via the $_GET array.
|
CWE-89
SQL Injection
|
CVE-2017-11444
|
2024-11-21 12:07 |
2017-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|