Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-07-23 CVE-2017-11528 Missing Release of Resource after Effective Lifetime vulnerability in Imagemagick
The ReadDIBImage function in coders/dib.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory leak) via a crafted file.
network
low complexity
imagemagick CWE-772
6.5
2017-07-23 CVE-2017-11527 Resource Exhaustion vulnerability in Imagemagick
The ReadDPXImage function in coders/dpx.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
network
low complexity
imagemagick CWE-400
6.5
2017-07-23 CVE-2017-11526 Resource Exhaustion vulnerability in Imagemagick
The ReadOneMNGImage function in coders/png.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted file.
network
low complexity
imagemagick CWE-400
6.5
2017-07-23 CVE-2017-11525 Allocation of Resources Without Limits or Throttling vulnerability in Imagemagick
The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
network
low complexity
imagemagick CWE-770
6.5
2017-07-23 CVE-2017-11524 Reachable Assertion vulnerability in Imagemagick
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
network
low complexity
imagemagick CWE-617
6.5
2017-07-22 CVE-2017-11523 Infinite Loop vulnerability in Imagemagick
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
network
low complexity
imagemagick CWE-835
6.5
2017-07-22 CVE-2017-11522 NULL Pointer Dereference vulnerability in Imagemagick
The WriteOnePNGImage function in coders/png.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
network
low complexity
imagemagick CWE-476
6.5
2017-07-22 CVE-2017-2274 Cross-site Scripting vulnerability in Buffalo Wmr-433 Firmware and Wmr-433W Firmware
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
buffalo CWE-79
6.1
2017-07-21 CVE-2017-1374 Information Exposure vulnerability in IBM Tririga Application Platform
Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system.
network
low complexity
ibm CWE-200
6.5
2017-07-21 CVE-2017-1372 Cross-site Scripting vulnerability in IBM Tririga Application Platform
IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
5.4