Vulnerabilities > Canonical > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2017-18029 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.6-10 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-12 CVE-2017-18028 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick canonical CWE-770
6.5
2018-01-12 CVE-2017-18027 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allow remote attackers to cause a denial of service via a crafted file.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-12 CVE-2018-5358 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the ReadPSDLayersInternal function in coders/psd.c.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-12 CVE-2018-5357 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-11 CVE-2018-5333 NULL Pointer Dereference vulnerability in multiple products
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.
local
low complexity
linux debian canonical CWE-476
5.5
2018-01-09 CVE-2017-15129 Race Condition vulnerability in multiple products
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11.
local
high complexity
linux fedoraproject canonical redhat CWE-362
4.7
2018-01-05 CVE-2018-5247 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-05 CVE-2018-5246 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c.
network
low complexity
imagemagick canonical CWE-772
6.5
2018-01-05 CVE-2017-18022 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.7-12 Q16, there are memory leaks in MontageImageCommand in MagickWand/montage.c.
network
low complexity
imagemagick canonical CWE-772
6.5