Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-07-31 CVE-2017-11358 Out-of-bounds Read vulnerability in multiple products
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
local
low complexity
sound-exchange-project debian CWE-125
5.5
2017-07-31 CVE-2017-11333 NULL Pointer Dereference vulnerability in Xiph.Org Libvorbis 1.3.5
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (OOM) via a crafted wav file.
local
low complexity
xiph-org CWE-476
5.5
2017-07-31 CVE-2017-11332 Divide By Zero vulnerability in multiple products
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
local
low complexity
sound-exchange-project debian CWE-369
5.5
2017-07-31 CVE-2017-11331 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Xiph Vorbis-Tools 1.4.0
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (memory allocation error) via a crafted wav file.
local
low complexity
xiph CWE-119
5.5
2017-07-31 CVE-2017-11330 Out-of-bounds Write vulnerability in Divfix Divfix++ 0.34
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denial of service (invalid memory write and application crash) via a crafted avi file.
local
low complexity
divfix CWE-787
5.5
2017-07-31 CVE-2017-11119 Out-of-bounds Read vulnerability in Nosefart Project Nosefart 2.9Mls
The chk_mem_access function in cpu/nes6502/nes6502.c in libnosefart.a in Nosefart 2.9-mls allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted nsf file.
local
low complexity
nosefart-project CWE-125
5.5
2017-07-31 CVE-2017-11118 Infinite Loop vulnerability in Openexif Project Openexif 2.1.4
The ExifImageFile::readImage function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted jpg file.
local
low complexity
openexif-project CWE-835
5.5
2017-07-31 CVE-2017-11117 Out-of-bounds Read vulnerability in Openexif Project Openexif 2.1.4
The ExifImageFile::readDHT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.
local
low complexity
openexif-project CWE-125
5.5
2017-07-31 CVE-2017-11115 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Openexif Project Openexif 2.1.4
The ExifJpegHUFFTable::deriveTable function in ExifHuffmanTable.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted jpg file.
local
low complexity
openexif-project CWE-119
5.5
2017-07-31 CVE-2017-11114 Out-of-bounds Read vulnerability in Twibright Links 2.14
The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.
local
low complexity
twibright CWE-125
5.5