Search CVE reports


Toggle filters

311 – 320 of 847 results


CVE-2017-17997

Medium priority

Some fixes available 3 of 4

In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-17935

Medium priority

Some fixes available 3 of 5

The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attackers to cause a denial of service (buffer underflow and application crash) via a...

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-16910

Low priority

Some fixes available 3 of 92

An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.

8 affected packages

darktable, dcraw, exactimage, rawtherapee, libraw...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Vulnerable Vulnerable Vulnerable Vulnerable
dcraw Vulnerable Vulnerable Vulnerable Vulnerable
exactimage Vulnerable Vulnerable Vulnerable Vulnerable
rawtherapee Vulnerable Vulnerable Vulnerable Vulnerable
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Vulnerable
kodi Needs evaluation Not affected Not affected Not affected
xbmc Not in release Not in release Not in release Not in release
Show all 8 packages Show less packages

CVE-2017-16909

Low priority

Some fixes available 3 of 91

An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.

8 affected packages

darktable, rawtherapee, libraw, ufraw, xbmc...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
darktable Needs evaluation Needs evaluation Ignored Ignored
rawtherapee Needs evaluation Needs evaluation Ignored Ignored
libraw Not affected Not affected Not affected Not affected
ufraw Not in release Not in release Not in release Ignored
xbmc Not in release Not in release Not in release Not in release
dcraw Needs evaluation Needs evaluation Ignored Ignored
kodi Needs evaluation Needs evaluation Ignored Ignored
exactimage Vulnerable Vulnerable Vulnerable Vulnerable
Show all 8 packages Show less packages

CVE-2017-17461

Medium priority
Ignored

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

1 affected package

node-marked

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-marked
Show less packages

CVE-2017-17085

Medium priority

Some fixes available 3 of 5

In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-17084

Medium priority

Some fixes available 3 of 5

In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the IWARP_MPA dissector could crash. This was addressed in epan/dissectors/packet-iwarp-mpa.c by validating a ULPDU length.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-17083

Medium priority

Some fixes available 3 of 5

In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the NetBIOS dissector could crash. This was addressed in epan/dissectors/packet-netbios.c by ensuring that write operations are bounded by the beginning of a buffer.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-15193

Medium priority

Some fixes available 3 of 5

In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the MBIM dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-mbim.c by changing the memory-allocation approach.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages

CVE-2017-15192

Medium priority

Some fixes available 3 of 5

In Wireshark 2.4.0 to 2.4.1 and 2.2.0 to 2.2.9, the BT ATT dissector could crash. This was addressed in epan/dissectors/packet-btatt.c by considering a case where not all of the BTATT packets have the same encapsulation level.

1 affected package

wireshark

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
wireshark Fixed
Show less packages