Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2017-12603 Out-of-bounds Write vulnerability in multiple products
OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 2-opencv-heapoverflow-fseek test case.
network
low complexity
opencv debian CWE-787
8.8
2017-08-07 CVE-2017-12602 Unspecified vulnerability in Opencv
OpenCV (Open Source Computer Vision Library) through 3.3 has a denial of service (memory consumption) issue, as demonstrated by the 10-opencv-dos-memory-exhaust test case.
network
low complexity
opencv
7.5
2017-08-07 CVE-2017-12601 Classic Buffer Overflow vulnerability in multiple products
OpenCV (Open Source Computer Vision Library) through 3.3 has a buffer overflow in the cv::BmpDecoder::readData function in modules/imgcodecs/src/grfmt_bmp.cpp when reading an image file by using cv::imread, as demonstrated by the 4-buf-overflow-readData-memcpy test case.
network
low complexity
opencv debian CWE-120
8.8
2017-08-07 CVE-2017-12600 Unspecified vulnerability in Opencv
OpenCV (Open Source Computer Vision Library) through 3.3 has a denial of service (CPU consumption) issue, as demonstrated by the 11-opencv-dos-cpu-exhaust test case.
network
low complexity
opencv
7.5
2017-08-07 CVE-2017-12599 Out-of-bounds Read vulnerability in multiple products
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an image file by using cv::imread.
network
low complexity
opencv debian CWE-125
8.8
2017-08-07 CVE-2017-12598 Out-of-bounds Read vulnerability in multiple products
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcodecs/src/bitstrm.cpp when reading an image file by using cv::imread, as demonstrated by the 8-opencv-invalid-read-fread test case.
network
low complexity
opencv debian CWE-125
8.8
2017-08-07 CVE-2017-12597 Out-of-bounds Write vulnerability in multiple products
OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image file by using cv::imread.
network
low complexity
opencv debian CWE-787
8.8
2017-08-07 CVE-2017-12596 Out-of-bounds Read vulnerability in Openexr 2.2.0
In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; it may result in denial of service or possibly unspecified other impact.
local
low complexity
openexr CWE-125
7.8
2017-08-06 CVE-2017-10677 Cross-Site Request Forgery (CSRF) vulnerability in Linksys Ea4500 Firmware 2.0.36
Cross-Site Request Forgery (CSRF) exists on Linksys EA4500 devices with Firmware Version before 2.1.41.164606, as demonstrated by a request to apply.cgi to disable SIP.
network
low complexity
linksys CWE-352
8.8
2017-08-06 CVE-2017-12587 Excessive Iteration vulnerability in Imagemagick 7.0.61
ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
network
low complexity
imagemagick CWE-834
8.8