Latest CVE Feed
-
5.5
MEDIUMCVE-2014-3464
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %0.19
- Published: Aug. 19, 2014
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-8694
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8695 and CVE-2016-8696.... Read more
- EPSS Score: %0.28
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0691
A denial of service vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36724453.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9836
ImageMagick 6.8.9-9 allows remote attackers to cause a denial of service via a crafted xpm file.... Read more
Affected Products : imagemagick- EPSS Score: %0.39
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9810
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file.... Read more
Affected Products : imagemagick- EPSS Score: %0.46
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10995
The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.... Read more
Affected Products : imagemagick- EPSS Score: %0.42
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11359
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.... Read more
- EPSS Score: %3.30
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11626
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObj... Read more
Affected Products : qpdf- EPSS Score: %0.34
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12192
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of s... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Oct. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-8808
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.... Read more
- EPSS Score: %0.53
- Published: Jul. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-13757
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafte... Read more
Affected Products : binutils- EPSS Score: %0.44
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14129
The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parse_comp_unit heap-based buffer over-read and application crash) v... Read more
Affected Products : binutils- EPSS Score: %0.44
- Published: Sep. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14934
process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in... Read more
Affected Products : binutils- EPSS Score: %0.45
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15023
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer derefer... Read more
Affected Products : binutils- EPSS Score: %0.45
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14932
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.... Read more
Affected Products : binutils- EPSS Score: %0.39
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-15299
The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspeci... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Oct. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2018-20362
A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the ... Read more
- EPSS Score: %0.35
- Published: Dec. 22, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-20673
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow... Read more
Affected Products : binutils- EPSS Score: %0.12
- Published: Jan. 04, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2015-4315
The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which allows remote authenticated users to read arbitrary files or cause a denial of service via a crafted XML ... Read more
Affected Products : telepresence_video_communication_server_software- EPSS Score: %0.46
- Published: Aug. 20, 2015
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2017-5837
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.... Read more
Affected Products : gstreamer- EPSS Score: %0.76
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025