| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-1000080 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets. | ||
| CVE-2017-1000079 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | Linux foundation ONOS 1.9.0 is vulnerable to a DoS. | ||
| CVE-2017-1000071 | Hig | 0.53 | 8.1 | 0.04 | Jul 17, 2017 | Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server. | ||
| CVE-2017-1000069 | Hig | 0.50 | 8.8 | 0.01 | Jul 17, 2017 | CSRF in Bitly oauth2_proxy 2.1 during authentication flow | ||
| CVE-2017-1000068 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disable arbitrary running splits and cause denial of service to clients in the field. | ||
| CVE-2017-1000067 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges. | ||
| CVE-2017-1000066 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information. | ||
| CVE-2017-1000064 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS | ||
| CVE-2017-1000062 | Hig | 0.49 | 7.5 | 0.04 | Jul 17, 2017 | kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution | ||
| CVE-2017-1000061 | Hig | 0.46 | 7.1 | 0.01 | Jul 17, 2017 | xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service | ||
| CVE-2017-1000053 | Hig | 0.53 | 8.1 | 0.02 | Jul 17, 2017 | Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session. | ||
| CVE-2017-1000052 | Hig | 0.51 | 7.8 | 0.00 | Jul 17, 2017 | Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. | ||
| CVE-2017-1000050 | Hig | 0.49 | 7.5 | 0.03 | Jul 17, 2017 | JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service. | ||
| CVE-2017-1000048 | Hig | 0.42 | 7.5 | 0.02 | Jul 17, 2017 | the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash. | ||
| CVE-2017-1000046 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | Mautic 2.6.1 and earlier fails to set flags on session cookies | ||
| CVE-2017-1000034 | Hig | 0.46 | 8.1 | 0.06 | Jul 17, 2017 | Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem. | ||
| CVE-2017-1000031 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters. | ||
| CVE-2017-1000029 | Hig | 0.49 | 7.5 | 0.08 | Jul 17, 2017 | Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication. | ||
| CVE-2017-1000028 | Hig | 0.60 | 7.5 | 0.99 | Jul 17, 2017 | Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request. | ||
| CVE-2017-1000026 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries | ||
| CVE-2017-1000025 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites. | ||
| CVE-2017-1000024 | Hig | 0.49 | 7.5 | 0.01 | Jul 17, 2017 | Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission | ||
| CVE-2017-1000022 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation. | ||
| CVE-2017-1000021 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents. | ||
| CVE-2017-1000018 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name | ||
| CVE-2017-1000017 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server | ||
| CVE-2017-1000016 | Hig | 0.42 | 7.5 | 0.01 | Jul 17, 2017 | A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18. | ||
| CVE-2017-1000014 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality | ||
| CVE-2017-1000010 | Hig | 0.51 | 7.8 | 0.02 | Jul 17, 2017 | Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution. | ||
| CVE-2017-1000008 | Hig | 0.57 | 8.8 | 0.01 | Jul 17, 2017 | Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password. | ||
| CVE-2017-1000001 | Hig | 0.49 | 7.5 | 0.02 | Jul 17, 2017 | FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on. | ||
| CVE-2017-0152 | Hig | 0.54 | 8.1 | 0.11 | Jul 17, 2017 | A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the… | ||
| CVE-2016-4996 | Hig | 0.46 | 7.0 | 0.00 | Jul 17, 2017 | discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading… | ||
| CVE-2015-5152 | Hig | 0.53 | 8.1 | 0.02 | Jul 17, 2017 | Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack. | ||
| CVE-2015-0249 | Hig | 0.47 | 7.2 | 0.05 | Jul 17, 2017 | The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL). | ||
| CVE-2017-11310 | Hig | 0.57 | 8.8 | 0.01 | Jul 13, 2017 | The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files. | ||
| CVE-2017-9789 | Hig | 0.50 | 7.5 | 0.10 | Jul 13, 2017 | When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour. | ||
| CVE-2017-6249 | Hig | 0.46 | 7.0 | 0.01 | Jul 13, 2017 | An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product:… | ||
| CVE-2017-9787 | Hig | 0.43 | 7.5 | 0.10 | Jul 13, 2017 | When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33. | ||
| CVE-2016-8951 | Hig | 0.49 | 7.5 | 0.03 | Jul 13, 2017 | IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. IBM X-Force ID: 118838. | ||
| CVE-2017-7529 | Hig | 0.54 | 7.5 | 0.63 | Jul 13, 2017 | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request. | ||
| CVE-2017-11103 | Hig | 0.53 | 8.1 | 0.05 | Jul 13, 2017 | Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the… | ||
| CVE-2017-11173 | Hig | 0.50 | 8.8 | 0.02 | Jul 13, 2017 | Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then… | ||
| CVE-2017-11200 | Hig | 0.57 | 8.8 | 0.01 | Jul 13, 2017 | SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter. | ||
| CVE-2017-11196 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2017 | Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page. | ||
| CVE-2017-11193 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2017 | Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker… | ||
| CVE-2017-2863 | Hig | 0.51 | 7.8 | 0.01 | Jul 12, 2017 | An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability. | ||
| CVE-2017-2820 | Hig | 0.58 | 8.8 | 0.04 | Jul 12, 2017 | An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary… | ||
| CVE-2017-2818 | Hig | 0.49 | 7.5 | 0.02 | Jul 12, 2017 | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be… | ||
| CVE-2017-2814 | Hig | 0.49 | 7.5 | 0.03 | Jul 12, 2017 | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker… |
- risk 0.49cvss 7.5epss 0.01
Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.
- risk 0.49cvss 7.5epss 0.01
Linux foundation ONOS 1.9.0 is vulnerable to a DoS.
- risk 0.53cvss 8.1epss 0.04
Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.
- risk 0.50cvss 8.8epss 0.01
CSRF in Bitly oauth2_proxy 2.1 during authentication flow
- risk 0.49cvss 7.5epss 0.02
TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disable arbitrary running splits and cause denial of service to clients in the field.
- risk 0.57cvss 8.8epss 0.01
MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.
- risk 0.49cvss 7.5epss 0.01
The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information.
- risk 0.49cvss 7.5epss 0.01
kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS
- risk 0.49cvss 7.5epss 0.04
kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution
- risk 0.46cvss 7.1epss 0.01
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service
- risk 0.53cvss 8.1epss 0.02
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.
- risk 0.51cvss 7.8epss 0.00
Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.
- risk 0.49cvss 7.5epss 0.03
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
- risk 0.42cvss 7.5epss 0.02
the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash.
- risk 0.49cvss 7.5epss 0.01
Mautic 2.6.1 and earlier fails to set flags on session cookies
- risk 0.46cvss 8.1epss 0.06
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability in graph_templates_inputs.php in Cacti 0.8.8b allows remote attackers to execute arbitrary SQL commands via the graph_template_input_id and graph_template_id parameters.
- risk 0.49cvss 7.5epss 0.08
Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.
- risk 0.60cvss 7.5epss 0.99
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Traversal vulnerability, that can be exploited by issuing a specially crafted HTTP GET request.
- risk 0.49cvss 7.5epss 0.02
Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries
- risk 0.49cvss 7.5epss 0.01
GNOME Web (Epiphany) 3.23 before 3.23.5, 3.22 before 3.22.6, 3.20 before 3.20.7, 3.18 before 3.18.11, and prior versions, is vulnerable to a password manager sweep attack resulting in the remote exfiltration of stored passwords for a selected set of websites.
- risk 0.49cvss 7.5epss 0.01
Shotwell version 0.24.4 or earlier and 0.25.3 or earlier is vulnerable to an information disclosure in the web publishing plugins resulting in potential password and oauth token plaintext transmission
- risk 0.57cvss 8.8epss 0.01
LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.
- risk 0.57cvss 8.8epss 0.01
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
- risk 0.49cvss 7.5epss 0.02
phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name
- risk 0.57cvss 8.8epss 0.01
phpMyAdmin 4.0, 4.4 and 4.6 are vulnerable to a weakness where a user with appropriate permissions is able to connect to an arbitrary MySQL server
- risk 0.42cvss 7.5epss 0.01
A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA-2016-18.
- risk 0.49cvss 7.5epss 0.02
phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality
- risk 0.51cvss 7.8epss 0.02
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
- risk 0.57cvss 8.8epss 0.01
Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.
- risk 0.49cvss 7.5epss 0.02
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
- risk 0.54cvss 8.1epss 0.11
A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the…
- risk 0.46cvss 7.0epss 0.00
discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading…
- risk 0.53cvss 8.1epss 0.02
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.
- risk 0.47cvss 7.2epss 0.05
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
- risk 0.57cvss 8.8epss 0.01
The read_user_chunk_callback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
- risk 0.50cvss 7.5epss 0.10
When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
- risk 0.46cvss 7.0epss 0.01
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product:…
- risk 0.43cvss 7.5epss 0.10
When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
- risk 0.49cvss 7.5epss 0.03
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. IBM X-Force ID: 118838.
- risk 0.54cvss 7.5epss 0.63
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
- risk 0.53cvss 8.1epss 0.05
Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the…
- risk 0.50cvss 8.8epss 0.02
Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then…
- risk 0.57cvss 8.8epss 0.01
SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.
- risk 0.57cvss 8.8epss 0.01
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.
- risk 0.57cvss 8.8epss 0.01
Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute, traceroute6, nslookup, arp, and Portprobe. These functions do not have any protections against CSRF. That can allow an attacker…
- risk 0.51cvss 7.8epss 0.01
An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.
- risk 0.58cvss 8.8epss 0.04
An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Poppler 0.53.0. A specially crafted PDF file can lead to an integer overflow causing out of bounds memory overwrite on the heap resulting in potential arbitrary…
- risk 0.49cvss 7.5epss 0.02
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted PDF can cause an overly large number of color components during image rendering, resulting in heap corruption. An attacker controlled PDF file can be…
- risk 0.49cvss 7.5epss 0.03
An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically crafted pdf can cause an image resizing after allocation has already occurred, resulting in heap corruption which can lead to code execution. An attacker…