CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write). | 7.8 |
High |
||
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory access) or possibly have unspecified other impact via a crafted ELF file. | 7.5 |
|||
The ELF parser in file 5.08 through 5.21 allows remote attackers to cause a denial of service via a large number of notes. | 5 |
|||
The ELF parser in file 5.16 through 5.21 allows remote attackers to cause a denial of service via a long string. | 5 |