Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-08-18 | CVE-2017-12937 | The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read. | Debian_linux, Graphicsmagick | 8.8 | ||
2017-08-22 | CVE-2017-13063 | GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12. | Debian_linux, Graphicsmagick | 6.5 | ||
2017-08-22 | CVE-2017-13064 | GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12. | Debian_linux, Graphicsmagick | 6.5 | ||
2017-08-22 | CVE-2017-13065 | GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c. | Debian_linux, Graphicsmagick | 6.5 | ||
2017-08-23 | CVE-2017-11610 | The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups. | Debian_linux, Fedora, Cloudforms, Supervisor | 8.8 | ||
2017-08-23 | CVE-2017-12904 | Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL. | Debian_linux, Newsbeuter | 8.8 | ||
2017-08-29 | CVE-2017-13737 | There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack. | Debian_linux, Graphicsmagick | 6.5 | ||
2017-08-29 | CVE-2017-13748 | There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack. | Debian_linux, Fedora, Jasper | 7.5 | ||
2017-08-29 | CVE-2017-0379 | Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c. | Debian_linux, Libgcrypt | 7.5 | ||
2017-08-30 | CVE-2017-13765 | In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plugins/irda/packet-ircomm.c by adding length validation. | Debian_linux, Wireshark | 7.5 |