Search

Found 1,064 results in 374ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-14325 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function PersistPixelCache in magick/cache.c, which allows attackers to cause a denial of service (memory consumption in ReadM…
CVE-2017-14228 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function paste_tokens() in preproc.c, aka a NULL pointer dereference. It will lead to remote denial of service.
CVE-2017-14175 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted XBM file, which claims large rows and co…
CVE-2017-14174 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large …
CVE-2017-14173 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In the function ReadTXTImage() in coders/txt.c in ImageMagick 7.0.6-10, an integer overflow might occur for the addition operation "GetQuantumRange(depth)+1" when "depth" is large, producing a smalle…
CVE-2017-14172 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" fi…
CVE-2017-14166 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchive 9y ago RHEA-2021:1580: libarchive bug fix and enhancement update (Moderate)
CVE-2017-12693 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadBMPImage function in coders/bmp.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted BMP file.
CVE-2017-12692 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadVIFFImage function in coders/viff.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted VIFF file.
CVE-2017-12691 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago The ReadOneLayer function in coders/xcf.c in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CVE-2017-14064 critical 9.8 9.8 slesdebian debian rhel ruby-lang 9y ago Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which …
CVE-2017-14060 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.6-10, a NULL Pointer Dereference issue is present in the ReadCUTImage function in coders/cut.c that could allow an attacker to cause a Denial of Service (in the QueueAuthenticPixel…
CVE-2017-13769 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file.
CVE-2017-13768 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Null Pointer Dereference in the IdentifyImage function in MagickCore/identify.c in ImageMagick through 7.0.6-10 allows an attacker to perform denial of service by sending a crafted image file.
CVE-2017-12877 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago Use-after-free vulnerability in the DestroyImage function in image.c in ImageMagick before 7.0.6-6 allows remote attackers to cause a denial of service via a crafted file.
CVE-2014-9637 medium 5.5 5.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
CVE-2017-13145 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.
CVE-2017-13139 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.
CVE-2016-6794 medium 5.3 5.3 slesdebian debian rhel apacheredhatnetapp 9y ago System Property Disclosure in Apache Tomcat
CVE-2016-5018 critical 9.1 9.1 slesdebian debian rhel apachenetappredhat 9y ago Authentication Bypass Using an Alternate Path or Channel in Apache Tomcat
CVE-2016-0762 medium 5.9 5.9 slesdebian debian rhel apacheredhatnetapp 9y ago Observable Discrepancy in Apache Tomcat
CVE-2017-12762 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux …
CVE-2017-11683 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVE-2015-1323 medium 5.5 5.5 ubuntu ubuntu 9y ago The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ub…
CVE-2017-11352 medium 6.5 6.5 FIX slesarch archdebian debian imagemagick 9y ago In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-91…
CVE-2017-9936 medium 6.5 7.5 EXPFIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9815 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function …
CVE-2017-9525 medium 6.7 6.7 FIX debian debianubuntu ubuntu cron_project 9y ago In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks aga…
CVE-2017-9473 medium 5.5 5.5 FIX debian debianubuntu ubuntu ytnef_project 9y ago In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CVE-2017-9471 medium 5.5 5.5 FIX debian debianubuntu ubuntu ytnef_project 9y ago In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CVE-2017-9404 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9403 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-6512 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu file\ 9y ago Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loos…
CVE-2017-9239 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage wi…
CVE-2017-9210 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop…
CVE-2017-9209 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpd…
CVE-2017-9208 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infi…
CVE-2016-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu zliboracleredhat 9y ago The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.
CVE-2016-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu zliboracleredhat 9y ago inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
CVE-2017-9117 medium 4.0 4.0 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by …
CVE-2017-9058 critical 9.8 9.8 FIX arch archdebian debianubuntu ubuntu ytnef_project 9y ago In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.
CVE-2017-8900 medium 4.6 4.6 FIX debian debianubuntu ubuntu lightdm_project 9y ago LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users…
CVE-2017-8831 medium 6.4 6.4 FIX slesdebian debian linux-kernel 9y ago The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly hav…
CVE-2017-6519 critical 9.1 9.1 FIX debian debian slesubuntu ubuntu avahi 9y ago avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (tra…
CVE-2017-7613 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CVE-2017-7612 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7611 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7610 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7608 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted…
CVE-2016-9388 medium 5.5 5.5 FIX arch arch slesubuntu ubuntu jasper_project 9y ago The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CVE-2017-5897 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu 9y ago The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds …
CVE-2014-9847 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu opensuse_projectimagemagick 9y ago The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
CVE-2014-9846 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
CVE-2014-9845 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
CVE-2014-9844 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
CVE-2014-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2014-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
CVE-2014-9853 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu imagemagicksuse 9y ago Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
CVE-2017-6590 medium 6.3 6.3 slesubuntu ubuntudebian debian 9y ago An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login s…
CVE-2015-8768 critical 9.8 9.8 ubuntu ubuntu click_project 9y ago click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges…
CVE-2016-2148 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu busybox 9y ago Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-9963 medium 5.9 5.9 FIX arch archdebian debianubuntu ubuntu exim 10y ago Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVE-2015-7977 medium 5.9 5.9 FIX slesdebian debianfedora fedora ntpnetapp 10y ago ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2015-7973 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu ntpnetapp 10y ago NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2017-3313 medium 4.7 4.7 slesdebian debian rhel oraclemariadb 10y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Dif…
CVE-2016-5824 medium 5.5 5.5 FIX sles rhelubuntu ubuntu libical_project 10y ago libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVE-2016-2090 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu freedesktop 10y ago Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-2375 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
CVE-2016-2373 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious…
CVE-2016-2372 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server,…
CVE-2016-2370 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A maliciou…
CVE-2016-2369 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a denial of service vulnera…
CVE-2016-2367 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server,…
CVE-2016-2366 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious…
CVE-2016-2365 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A mali…
CVE-2016-6313 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu gnupg 10y ago The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of …
CVE-2016-9013 critical 9.8 9.8 FIX slesarch archubuntu ubuntu djangoproject 10y ago Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it eas…
CVE-2016-9318 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu xmlsoftxmlsec_project 10y ago libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, …
CVE-2016-7795 medium 5.5 5.5 FIX slesarch archubuntu ubuntu systemd_project 10y ago denial of service in systemd
CVE-2016-7117 critical 9.8 9.8 FIX slesdebian debian linux-kernel 10y ago Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system …
CVE-2016-1372 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu clamav 10y ago ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
CVE-2016-1371 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu clamav 10y ago ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
CVE-2016-5180 critical 9.8 9.8 FIX slesdebian debianarch arch c-aresc-ares_projectnodejs 10y ago Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code …
CVE-2016-6306 medium 5.9 5.9 FIX slesarch archdebian debian opensslhpnodejs 10y ago The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s…
CVE-2015-8934 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ra…
CVE-2015-8933 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafte…
CVE-2015-8932 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which trigg…
CVE-2015-8928 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
CVE-2015-8926 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
CVE-2015-8925 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newlin…
CVE-2015-8924 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafte…
CVE-2015-8923 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
CVE-2015-8922 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7…
CVE-2015-8920 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu novelllibarchive 10y ago The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
CVE-2015-8916 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NU…
CVE-2016-6351 medium 6.7 6.7 FIX slesdebian debianubuntu ubuntu qemu 10y ago The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (ou…
CVE-2016-5107 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds re…
CVE-2016-5106 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of …
CVE-2016-5105 medium 4.4 4.4 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest admi…
CVE-2016-4952 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vec…