Latest CVE Feed
-
9.8
CRITICALCVE-2017-9152
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the pnm_load_raw function in input-pnm.c:346:41.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9093
The my_skip_input_data_fn function in imagew-jpeg.c in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted image.... Read more
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9117
In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by a heap-based buffer over-read in bmp2tiff. NOTE: mention... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9173
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:497:29.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9116
In OpenEXR 2.2.0, an invalid read of size 1 in the uncompress function in ImfZip.cpp could cause the application to crash.... Read more
Affected Products : openexr- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9146
The TNEFFillMapi function in lib/ytnef.c in libytnef in ytnef through 1.9.2 does not ensure a nonzero count value before a certain memory allocation, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application cr... Read more
Affected Products : ytnef- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9127
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.... Read more
Affected Products : libquicktime- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9125
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted mp4 file.... Read more
Affected Products : libquicktime- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9164
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9123
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.... Read more
Affected Products : libquicktime- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9159
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the pnm_load_rawpbm function in input-pnm.c:391:15.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9129
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.... Read more
Affected Products : freeware_advanced_audio_coder- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-9138
There is a debug-interface vulnerability on some Tenda routers (FH1202/F1202/F1200: versions before 1.2.0.20). After connecting locally to a router in a wired or wireless manner, one can bypass intended access restrictions by sending shell commands direct... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9131
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its clients, an attacker can gather enough information to craft a command that reboot... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9162
libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in autotrace.c:191:2.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9178
libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the ReadImage function in input-bmp.c:421:11.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9147
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash) via a crafted TIFF file.... Read more
Affected Products : libtiff- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9169
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:355:25.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9151
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the pnm_load_ascii function in input-pnm.c:303:12.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9167
libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-bmp.c:337:25.... Read more
Affected Products : autotrace- Published: May. 23, 2017
- Modified: Apr. 20, 2025