Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In September 2017
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.
CVSS Score
9.8
EPSS Score
0.079
Published
2017-09-29
In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-09-29
There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
CVSS Score
5.5
EPSS Score
0.002
Published
2017-09-29
An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-29
There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-09-29
There is a stack consumption vulnerability in the Exiv2::Internal::stringFormat function of image.cpp in Exiv2 0.26. A Crafted input will lead to a remote denial of service attack.
CVSS Score
5.5
EPSS Score
0.004
Published
2017-09-29
An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-29
A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-09-29
An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
CVSS Score
5.5
EPSS Score
0.001
Published
2017-09-29
There is a heap-based buffer overflow in the Exiv2::us2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
CVSS Score
5.5
EPSS Score
0.003
Published
2017-09-29


Contact Us

Shodan ® - All rights reserved