Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-06-26 CVE-2017-9936 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c.
network
low complexity
libtiff debian canonical CWE-772
6.5
2017-06-26 CVE-2017-9929 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
long-range-zip-project debian CWE-119
5.5
2017-06-26 CVE-2017-9928 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service via a crafted file.
local
low complexity
long-range-zip-project debian CWE-119
5.5
2017-06-26 CVE-2017-7416 Cross-site Scripting vulnerability in Ntop Ntopng
ntopng before 3.0 allows XSS because GET and POST parameters are improperly validated.
network
low complexity
ntop CWE-79
6.1
2017-06-25 CVE-2017-9870 Out-of-bounds Read vulnerability in Lame Project Lame 3.99.5
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file that is mishandled in the code for the "block_type == 2" case, a similar issue to CVE-2017-11126.
local
low complexity
lame-project CWE-125
5.5
2017-06-25 CVE-2017-9869 Out-of-bounds Read vulnerability in Lame Project Lame 3.99.5
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.
local
low complexity
lame-project CWE-125
5.5
2017-06-25 CVE-2015-9101 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Lame Project Lame
The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.98.4, 3.98.2, 3.98, 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4 and 3.99.5 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.
local
low complexity
lame-project CWE-119
5.5
2017-06-25 CVE-2015-9100 NULL Pointer Dereference vulnerability in Lame Project Lame 3.99.5
The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.
local
low complexity
lame-project CWE-476
5.5
2017-06-25 CVE-2015-9099 Out-of-bounds Read vulnerability in Lame Project Lame 3.99.5
The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file with a negative sample rate.
local
low complexity
lame-project CWE-125
5.5
2017-06-25 CVE-2017-9868 Information Exposure vulnerability in multiple products
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
local
low complexity
eclipse debian CWE-200
5.5