Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-07-31 CVE-2017-11332 Divide By Zero vulnerability in multiple products
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
local
low complexity
sound-exchange-project debian CWE-369
5.5
2017-07-29 CVE-2017-11733 NULL Pointer Dereference vulnerability in multiple products
A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
libming debian CWE-476
5.5
2017-07-29 CVE-2017-11732 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
libming debian CWE-119
5.5
2017-07-27 CVE-2017-11683 Reachable Assertion vulnerability in multiple products
There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
network
low complexity
exiv2 canonical debian CWE-617
6.5
2017-07-25 CVE-2017-11434 Out-of-bounds Read vulnerability in multiple products
The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) via a crafted DHCP options string.
local
low complexity
qemu debian CWE-125
5.5
2017-07-17 CVE-2017-11352 In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.
network
low complexity
imagemagick debian canonical
6.5
2017-07-08 CVE-2017-11107 Cross-site Scripting vulnerability in multiple products
phpLDAPadmin through 1.2.3 has XSS in htdocs/entry_chooser.php via the form, element, rdn, or container parameter.
network
low complexity
phpldapadmin-project debian CWE-79
6.1
2017-07-08 CVE-2017-11104 Improper Input Validation vulnerability in multiple products
Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG authentication if no additional ACL restrictions are set, because of an improper TSIG validity period check.
network
high complexity
knot-dns debian CWE-20
5.9
2017-06-28 CVE-2017-9989 NULL Pointer Dereference vulnerability in multiple products
util/outputtxt.c in libming 0.4.8 mishandles memory allocation.
network
low complexity
libming debian CWE-476
6.5
2017-06-28 CVE-2017-9988 NULL Pointer Dereference vulnerability in multiple products
The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation.
network
low complexity
libming debian CWE-476
6.5