Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Alphafuzzer

#13536of 53,622
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2015-7774
9.8
2015-12-02
Libraw · Libraw · CVE-2015-8366
**Name of the Vulnerable Software and Affected Versions** LibRaw versions prior to 0.17.1 **Description** The issue is related to an array index error in the `smal decode segment` function, which can be exploited by context-dependent attackers to cause memory errors and potentially execute arbitrary code. This is achieved through vectors related to indexes. **Recommendations** For versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue.
PT-2015-7775
9.8
2015-12-02
Libraw · Libraw · CVE-2015-8367
**Name of the Vulnerable Software and Affected Versions** Libraw versions prior to 0.17.1 **Description** The issue is related to memory object initialization in the `phase one correct` function, which can cause memory errors and potentially allow attackers to execute arbitrary code. **Recommendations** For versions prior to 0.17.1, update to version 0.17.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the `phase one correct` function until a patch is available.