Latest CVE Feed
-
7.8
HIGHCVE-2016-10054
Buffer overflow in the WriteMAPImage function in coders/map.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10053
The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10052
Buffer overflow in the WriteProfile function in coders/jpeg.c in ImageMagick before 6.9.5-6 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10051
Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10050
Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10049
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10048
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-10047
Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10046
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9915
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.... Read more
Affected Products : imagemagick- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-8731
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.... Read more
Affected Products : phpmemcachedadmin- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-7279
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7199
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is running in Agent Mode. Version 6.10.4 fixes this issue.... Read more
Affected Products : nessus- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6361
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : qts- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information via unspecified vectors.... Read more
Affected Products : qts- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6359
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands via unspecified vectors.... Read more
Affected Products : qts- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6191
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.... Read more
Affected Products : apng_disassembler- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5897
The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds access.... Read more
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5538
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bound... Read more
Affected Products : samsung_mobile- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-5524
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.... Read more
Affected Products : plone- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025