Christos Zoulas File vulnerabilities
8 known vulnerabilities affecting christos_zoulas/file.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2014-3587MEDIUMCVSS 4.3≤ 5.19v5.00+18 more2014-08-23
CVE-2014-3587 [MEDIUM] CVE-2014-3587: Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in th
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
nvd
CVE-2014-0207MEDIUMCVSS 6.5fixed in 5.192014-07-09
CVE-2014-0207 [MEDIUM] CWE-119 CVE-2014-0207: The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component i
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted CDF file.
nvd
CVE-2014-3478MEDIUMCVSS 6.5≤ 5.18v5.00+17 more2014-07-09
CVE-2014-3478 [MEDIUM] CWE-119 CVE-2014-3478: Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (application crash) via a crafted Pascal string in a FILE_PSTRING conversion.
nvd
CVE-2014-3538MEDIUMCVSS 5.0≤ 5.18v5.00+17 more2014-07-03
CVE-2014-3538 [MEDIUM] CVE-2014-3538: file before 5.19 does not properly restrict the amount of data read during a regex search, which all
file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7345.
nvd
CVE-2013-7345MEDIUMCVSS 5.0fixed in 5.152014-03-24
CVE-2013-7345 [MEDIUM] CVE-2013-7345: The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15
The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline char
nvd
CVE-2012-1571MEDIUMCVSS 6.5≤ 5.102012-07-17
CVE-2012-1571 [MEDIUM] CWE-119 CVE-2012-1571: file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a craf
file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that triggers (1) an out-of-bounds read or (2) an invalid pointer dereference.
nvd
CVE-2009-3930CRITICALCVSS 9.3≤ 5.01v3.30+33 more2009-11-10
CVE-2009-3930 [CRITICAL] CWE-189 CVE-2009-3930: Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers
Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file that triggers a buffer overflow.
nvd
CVE-2009-1515MEDIUMCVSS 6.8v5.002009-05-04
CVE-2009-1515 [MEDIUM] CWE-119 CVE-2009-1515: Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 al
Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.
nvd