Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2017-05-02 CVE-2017-8112 Infinite Loop vulnerability in multiple products
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (infinite loop and CPU consumption) via the message ring page count.
local
low complexity
qemu debian CWE-835
6.5
2017-05-02 CVE-2017-8086 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (memory consumption) via vectors involving the orig_value variable.
local
low complexity
qemu debian CWE-772
6.5
2017-05-02 CVE-2017-7483 Out-of-bounds Read vulnerability in multiple products
Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible integer that eventually leads to a segfault due to an out of bounds read.
network
low complexity
rxvt-project debian CWE-125
7.5
2017-05-02 CVE-2016-10243 Improper Input Validation vulnerability in multiple products
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
network
low complexity
debian fedoraproject tug CWE-20
critical
9.8
2017-04-30 CVE-2017-8365 Out-of-bounds Read vulnerability in multiple products
The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
network
low complexity
libsndfile-project debian CWE-125
6.5
2017-04-30 CVE-2017-8363 Out-of-bounds Read vulnerability in multiple products
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
network
low complexity
libsndfile-project debian CWE-125
6.5
2017-04-30 CVE-2017-8362 Out-of-bounds Read vulnerability in multiple products
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.
network
low complexity
libsndfile-project debian CWE-125
6.5
2017-04-30 CVE-2017-8361 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.
network
low complexity
libsndfile-project debian CWE-119
8.8
2017-04-30 CVE-2017-8357 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.5-5, the ReadEPTImage function in ept.c allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick debian CWE-772
6.5
2017-04-30 CVE-2017-8356 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In ImageMagick 7.0.5-5, the ReadSUNImage function in sun.c allows attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick debian CWE-772
6.5