Vulnerabilities > Debian > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-02-22 | CVE-2017-6188 | Improper Input Validation vulnerability in multiple products Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. | 5.5 |
2017-02-17 | CVE-2016-9955 | Improper Input Validation vulnerability in multiple products The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean. | 6.3 |
2017-02-16 | CVE-2017-6011 | Out-of-bounds Read vulnerability in multiple products An issue was discovered in icoutils 0.31.1. | 5.5 |
2017-02-16 | CVE-2017-6010 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products An issue was discovered in icoutils 0.31.1. | 5.5 |
2017-02-16 | CVE-2017-6009 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products An issue was discovered in icoutils 0.31.1. | 5.5 |
2017-02-15 | CVE-2016-8692 | Divide By Zero vulnerability in multiple products The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command. | 5.5 |
2017-02-15 | CVE-2016-8691 | Divide By Zero vulnerability in multiple products The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command. | 5.5 |
2017-02-06 | CVE-2016-9532 | Out-of-bounds Read vulnerability in multiple products Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file. | 5.5 |
2017-02-03 | CVE-2016-5241 | Numeric Errors vulnerability in multiple products magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file. | 5.5 |
2017-02-03 | CVE-2016-4571 | Resource Exhaustion vulnerability in multiple products The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file. | 5.5 |