Vulnerabilities > Debian > Debian Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-02 CVE-2017-1000422 Integer Overflow or Wraparound vulnerability in multiple products
Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution
6.8
2018-01-02 CVE-2017-1000456 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.
6.8
2018-01-02 CVE-2017-1000450 Integer Overflow or Wraparound vulnerability in multiple products
In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow.
6.8
2018-01-02 CVE-2017-1000445 NULL Pointer Dereference vulnerability in multiple products
ImageMagick 7.0.7-1 and older version are vulnerable to null pointer dereference in the MagickCore component and might lead to denial of service
4.3
2017-12-31 CVE-2017-18005 NULL Pointer Dereference vulnerability in multiple products
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.
local
low complexity
exiv2 debian CWE-476
5.5
2017-12-29 CVE-2017-17760 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.
4.3
2017-12-27 CVE-2017-17915 Out-of-bounds Read vulnerability in multiple products
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
6.8
2017-12-27 CVE-2017-17913 Out-of-bounds Read vulnerability in multiple products
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.
6.8
2017-12-27 CVE-2017-17912 Out-of-bounds Read vulnerability in multiple products
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.
6.8
2017-12-27 CVE-2017-17879 Out-of-bounds Read vulnerability in multiple products
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
6.8