CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103132  CVE-2017-6312  Candidate  Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.  Assigned (20170223)  None (candidate not yet proposed)    View
103133  CVE-2017-6313  Candidate  Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO file.  Assigned (20170223)  None (candidate not yet proposed)    View
103134  CVE-2017-6314  Candidate  The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.  Assigned (20170223)  None (candidate not yet proposed)    View
103006  CVE-2017-6186  Candidate  Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, inject arbitrary code, and take full control of any Bitdefender process via a "DoubleAgent" attack. One perspective on this issue is that (1) these products do not use the Protected Processes feature, and therefore an attacker can enter an arbitrary Application Verifier Provider DLL under Image File Execution Options in the registry; (2) the self-protection mechanism is intended to block all local processes (regardless of privileges) from modifying Image File Execution Options for these products; and (3) this mechanism can be bypassed by an attacker who temporarily renames Image File Execution Options during the attack.  Assigned (20170222)  None (candidate not yet proposed)    View
103007  CVE-2017-6187  Candidate  Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.  Assigned (20170222)  None (candidate not yet proposed)    View

Page 956 of 20943, showing 5 records out of 104715 total, starting on record 4776, ending on 4780

Actions