Subscribe via feed.
Archive for August, 2017

OpenExif 2.1.4 Denial Of Service

Posted by deepcore under exploit (No Respond)

The ExifJpegHUFFTable::deriveTable function in src/ExifHuffmanTable.cpp in OpenExif version 2.1.4 can cause a denial of service (heap buffer overflow and application crash) via a crafted jpg file.

Nosefart 2.9-mis Denial Of Service

Posted by deepcore under exploit (No Respond)

Nosefart version 2.9-mis suffers from a denial of service vulnerability.

DivFix++ 0.34 Denial Of Service

Posted by deepcore under exploit (No Respond)

DivFix++ version 0.34 suffers from a denial of service vulnerability.

vorbis-tools oggenc 1.4.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

The wav_open function in oggenc/audio.c in vorbis-tools version 1.4.0 can cause a denial of service (memory allocation error) via a crafted wav file.

libao 1.2.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

The _tokenize_matrix function in audio_out.c in Xiph.Org libao version 1.2.0 can cause a denial of service (memory corruption) via a crafted mp3 file.

libmad 0.15.1b Denial Of Service

Posted by deepcore under exploit (No Respond)

The mad_decoder_run function in decoder.c in libmad version 0.15.1b can cause a denial of service (memory corruption) via a crafted mp3 file.

Libid3tag 0.15.1b Denial Of Service

Posted by deepcore under exploit (No Respond)

The id3_ucs4_length function in ucs4.c in libid3tag version 0.15.1b can cause a denial of service (NULL Pointer Dereference and application crash) via a crafted mp3 file.

TiMidity++ 2.14.0 Denial Of Service

Posted by deepcore under exploit (No Respond)

The insert_note_steps function in readmidi.c in TiMidity++ version 2.14.0 can cause a denial of service (divide-by-zero error and application crash) via a crafted mid file.

Salutation Responsive 3.0.15 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 suffers from a persistent cross site scripting vulnerability.

Sound eXchange (SoX) 14.4.2 Denial Of Service

Posted by deepcore under exploit (No Respond)

The startread function in wav.c in Sound eXchange(SoX) version 14.4.2 can cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.