Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-12 CVE-2017-15281 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised value(s)."
network
low complexity
imagemagick canonical CWE-119
8.8
2017-10-11 CVE-2017-8025 Improper Input Validation vulnerability in EMC Archer GRC Platform 6.2.0.4
RSA Archer GRC Platform prior to 6.2.0.5 is affected by an arbitrary file upload vulnerability.
local
high complexity
emc CWE-20
7.4
2017-10-11 CVE-2017-2888 Integer Overflow or Wraparound vulnerability in multiple products
An exploitable integer overflow vulnerability exists when creating a new RGB Surface in SDL 2.0.5.
network
low complexity
libsdl canonical debian CWE-190
8.8
2017-10-11 CVE-2017-2887 Out-of-bounds Write vulnerability in multiple products
An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1.
network
low complexity
libsdl debian CWE-787
8.8
2017-10-11 CVE-2017-15264 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview 4.44
IrfanView version 4.44 (32bit) allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at image00000000_00400000+0x00000000000236e4."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15263 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlListWalk+0x00000000000166c4."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15262 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x0000000000048d0c."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15261 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to a "Possible Stack Corruption starting at PDF!xmlGetGlobalState+0x0000000000057b35."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15260 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlParserInputRead+0x0000000000129a59."
local
low complexity
irfanview CWE-119
7.8
2017-10-11 CVE-2017-15259 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Irfanview and PDF
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at PDF!xmlParserInputRead+0x000000000011624a."
local
low complexity
irfanview CWE-119
7.8