Vulnerabilities > Squashfs Project

DATE CVE VULNERABILITY TITLE RISK
2017-04-13 CVE-2015-4646 Improper Input Validation vulnerability in Squashfs Project Squashfs
(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of service (application crash) via a crafted input.
network
low complexity
squashfs-project CWE-20
7.5
2017-03-17 CVE-2015-4645 Integer Overflow or Wraparound vulnerability in multiple products
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
local
low complexity
squashfs-project fedoraproject CWE-190
5.5