Vulnerabilities > File Project > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-08-22 | CVE-2022-48554 | Out-of-bounds Read vulnerability in multiple products File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. | 5.5 |
2019-02-18 | CVE-2019-8907 | Out-of-bounds Write vulnerability in multiple products do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact. | 6.8 |
2019-02-18 | CVE-2019-8904 | Out-of-bounds Read vulnerability in multiple products do_bid_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printf and file_vprintf. | 6.8 |
2018-06-11 | CVE-2018-10360 | Out-of-bounds Read vulnerability in multiple products The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file. | 4.3 |
2015-03-30 | CVE-2014-9652 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in PHP The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote attackers to cause a denial of service (out-of-bounds memory access and application crash) via a crafted file. | 5.0 |
2015-01-21 | CVE-2014-9621 | Resource Management Errors vulnerability in File Project File The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string. | 5.0 |
2015-01-21 | CVE-2014-9620 | Resource Management Errors vulnerability in File Project File The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes. | 5.0 |
2014-12-17 | CVE-2014-8117 | Resource Management Errors vulnerability in multiple products softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors. | 5.0 |
2014-12-17 | CVE-2014-8116 | Resource Management Errors vulnerability in multiple products The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. | 5.0 |