Search CVE reports


Toggle filters

38551 – 38560 of 62102 results


CVE-2017-13145

Medium priority

Some fixes available 1 of 2

In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected
Show less packages

CVE-2017-13144

Negligible priority

Some fixes available 2 of 3

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, as demonstrated by use of the mpc coder.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-13143

Medium priority

Some fixes available 2 of 3

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote attackers to obtain sensitive information from process memory.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected
Show less packages

CVE-2017-13142

Medium priority

Some fixes available 2 of 3

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash because there was an insufficient check for short files.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected
Show less packages

CVE-2017-13139

Medium priority

Some fixes available 2 of 3

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

1 affected package

imagemagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
imagemagick Not affected
Show less packages

CVE-2017-12809

Low priority
Fixed

QEMU (aka Quick Emulator), when built with the IDE disk and CD/DVD-ROM Emulator support, allows local guest OS privileged users to cause a denial of service (NULL pointer dereference and QEMU process crash) by flushing an empty...

2 affected packages

qemu, qemu-kvm

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
qemu
qemu-kvm
Show less packages

CVE-2016-2102

Medium priority
Ignored

HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.

1 affected package

tripleo-image-elements

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-image-elements Not affected
Show less packages

CVE-2017-7557

Medium priority
Vulnerable

dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-12843

Medium priority
Not affected

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.

2 affected packages

cyrus-imapd, cyrus-imapd-2.4

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cyrus-imapd
cyrus-imapd-2.4
Show less packages

CVE-2017-13066

Low priority
Vulnerable

GraphicsMagick 1.3.26 has a memory leak vulnerability in the function CloneImage in magick/image.c.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected Not affected
Show less packages