Vulnerabilities > Improper Input Validation

DATE CVE VULNERABILITY TITLE RISK
2017-04-09 CVE-2017-7613 Improper Input Validation vulnerability in multiple products
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
local
low complexity
elfutils-project debian canonical CWE-20
5.5
2017-04-09 CVE-2017-7609 Improper Input Validation vulnerability in Elfutils Project Elfutils 0.168
elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
local
low complexity
elfutils-project CWE-20
5.5
2017-04-09 CVE-2017-7606 Improper Input Validation vulnerability in Imagemagick 7.0.54
coders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
network
low complexity
imagemagick CWE-20
6.5
2017-04-09 CVE-2017-7604 Improper Input Validation vulnerability in Libaacplus Project Libaacplus 2.0.2
au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file.
local
low complexity
libaacplus-project CWE-20
7.8
2017-04-09 CVE-2017-7601 Improper Input Validation vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8
2017-04-09 CVE-2017-7600 Improper Input Validation vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8
2017-04-09 CVE-2017-7599 Improper Input Validation vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8
2017-04-09 CVE-2017-7597 Improper Input Validation vulnerability in Libtiff 4.0.7
tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8
2017-04-09 CVE-2017-7596 Improper Input Validation vulnerability in Libtiff 4.0.7
LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8
2017-04-09 CVE-2017-7592 Improper Input Validation vulnerability in Libtiff 4.0.7
The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.
local
low complexity
libtiff CWE-20
7.8