Vulnerabilities > File Project > File
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-22 | CVE-2022-48554 | Out-of-bounds Read vulnerability in multiple products File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. | 5.5 |
2019-10-21 | CVE-2019-18218 | Out-of-bounds Write vulnerability in multiple products cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). | 7.8 |
2019-02-18 | CVE-2019-8907 | Out-of-bounds Write vulnerability in multiple products do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. | 6.8 |
2019-02-18 | CVE-2019-8906 | Out-of-bounds Read vulnerability in multiple products do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused. | 3.6 |
2019-02-18 | CVE-2019-8905 | Out-of-bounds Read vulnerability in multiple products do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. | 3.6 |
2019-02-18 | CVE-2019-8904 | Out-of-bounds Read vulnerability in multiple products do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. | 6.8 |
2018-06-11 | CVE-2018-10360 | Out-of-bounds Read vulnerability in multiple products The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file. | 4.3 |
2017-09-11 | CVE-2017-1000249 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in File Project File 5.29 An issue in file() was introduced in commit 9611f31313a93aa036389c5f3b15eea53510d4d1 (Oct 2016) lets an attacker overwrite a fixed 20 bytes stack buffer with a specially crafted .notes section in an ELF binary. | 2.1 |
2015-03-30 | CVE-2014-9653 | Improper Input Validation vulnerability in multiple products readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file. | 7.5 |
2015-03-30 | CVE-2014-9652 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in PHP The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file. | 5.0 |