Search CVE reports


Toggle filters

31 – 40 of 142 results


CVE-2017-6886

Low priority

Some fixes available 3 of 113

An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.

12 affected packages

darktable, flphoto, dcraw, exactimage, kodi...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Needs evaluation Needs evaluation
flphoto Not in release Not in release Not in release Not in release
dcraw Needs evaluation Needs evaluation Needs evaluation Needs evaluation
exactimage Vulnerable Vulnerable Vulnerable Vulnerable
kodi Needs evaluation Needs evaluation Needs evaluation Needs evaluation
rawtherapee Needs evaluation Needs evaluation Needs evaluation Needs evaluation
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Needs evaluation
rawstudio Not in release Not in release Not in release Not in release
freeimage Not affected Not affected Not affected Not affected
graphicsmagick Not affected Not affected Not affected Not affected
xbmc Not in release Not in release Not in release Not in release
Show all 12 packages Show less packages

CVE-2017-6335

Low priority

Some fixes available 1 of 3

The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2017-18231

Medium priority

Some fixes available 2 of 3

An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadEnhMetaFile in coders/emf.c, which allows attackers to cause a denial of service via a crafted file.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-18230

Medium priority

Some fixes available 2 of 3

An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-18229

Medium priority

Some fixes available 2 of 3

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-18220

Medium priority
Fixed

The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-18219

Low priority

Some fixes available 2 of 3

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers...

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-17915

Medium priority

Some fixes available 2 of 4

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages

CVE-2017-17913

Medium priority

Some fixes available 1 of 3

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected
Show less packages

CVE-2017-17912

Medium priority

Some fixes available 2 of 4

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.

1 affected package

graphicsmagick

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
graphicsmagick Not affected Not affected Not affected
Show less packages