Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In March 2017
The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).
CVSS Score
5.5
EPSS Score
0.002
Published
2017-03-23
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.
CVSS Score
5.5
EPSS Score
0.005
Published
2017-03-23
Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
CVSS Score
5.5
EPSS Score
0.004
Published
2017-03-23
Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
CVSS Score
5.5
EPSS Score
0.002
Published
2017-03-23
The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.
CVSS Score
5.5
EPSS Score
0.002
Published
2017-03-23
listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.
CVSS Score
6.5
EPSS Score
0.007
Published
2017-03-23
Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).
CVSS Score
7.5
EPSS Score
0.007
Published
2017-03-23
The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).
CVSS Score
7.5
EPSS Score
0.008
Published
2017-03-23
Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, which triggers an assertion failure.
CVSS Score
7.8
EPSS Score
0.003
Published
2017-03-23
The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-03-23


Contact Us

Shodan ® - All rights reserved