NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87094  CVE-2017-9502  In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes. If the default protocol is specified to be FILE or a file: URL lacks two slashes, the given URL starts with a drive letter, and libcurl is built for Windows or DOS, then libcurl would copy the path 7 bytes off, so that the end of the given path would write beyond the malloc buffer (7 bytes being the length in bytes of the ascii string file://).    Medium  2017-07-18  2017-07-07  View
86707  CVE-2017-9501  In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.    4.3  Medium  2017-06-17  2017-06-12  View
86706  CVE-2017-9500  In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.    4.3  Medium  2017-06-17  2017-06-12  View
86705  CVE-2017-9499  In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.    4.3  Medium  2017-06-17  2017-06-12  View
86704  CVE-2017-9474  In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.    4.3  Medium  2017-06-12  2017-06-09  View

Page 52 of 17672, showing 5 records out of 88360 total, starting on record 256, ending on 260

Actions