Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-12-04 CVE-2017-17130 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libav 12.2
The ff_free_picture_tables function in libavcodec/mpegpicture.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to vc1_decode_i_blocks_adv.
network
low complexity
libav CWE-119
8.8
2017-12-04 CVE-2017-17129 NULL Pointer Dereference vulnerability in Libav 12.2
The ff_vc1_mc_4mv_chroma4 function in libavcodec/vc1_mc.c in Libav 12.2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly have unspecified other impact via a crafted file.
network
low complexity
libav CWE-476
8.8
2017-12-04 CVE-2017-17126 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.29.1
The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via an ELF file that lacks section headers.
local
low complexity
gnu CWE-119
7.8
2017-12-04 CVE-2017-17125 Out-of-bounds Read vulnerability in GNU Binutils 2.29.1
nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_symbol_version_string buffer over-read and application crash) or possibly have unspecified other impact via a crafted ELF file.
local
low complexity
gnu CWE-125
7.8
2017-12-04 CVE-2017-17124 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.29.1
The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate the size of the external string table, which allows remote attackers to cause a denial of service (excessive memory consumption, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted COFF binary.
local
low complexity
gnu CWE-119
7.8
2017-12-04 CVE-2017-17122 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.29.1
The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attackers to cause a denial of service (excessive memory allocation, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PE file.
local
low complexity
gnu CWE-190
7.8
2017-12-04 CVE-2017-17121 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils 2.29.1
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (memory access violation) or possibly have unspecified other impact via a COFF binary in which a relocation refers to a location after the end of the to-be-relocated section.
local
low complexity
gnu CWE-119
7.8
2017-12-04 CVE-2017-17114 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ikarussecurity Anti.Virus 2.16.15
ntguard.sys and ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 have a Memory Corruption vulnerability via a 0x83000084 DeviceIoControl request.
local
low complexity
ikarussecurity CWE-119
7.8
2017-12-04 CVE-2017-17112 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Ikarussecurity Anti.Virus 2.16.15
ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 has a Pool Corruption vulnerability via a 0x83000058 DeviceIoControl request.
local
low complexity
ikarussecurity CWE-119
7.8
2017-12-04 CVE-2017-17104 Information Exposure vulnerability in Fiyo CMS 2.0.7
Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].
network
low complexity
fiyo CWE-200
7.5