Search

Found 2,417 results in 420ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-8863 critical 9.8 9.8 debian debian libupnp_project 9y ago Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possi…
CVE-2016-7407 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
CVE-2016-7406 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
CVE-2016-10204 critical 9.8 9.8 FIX debian debian zoneminder 9y ago SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2016-10127 critical 9.0 9.0 slesdebian debian pysaml2_project 9y ago PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVE-2017-5885 critical 9.8 9.8 FIX slesdebian debianfedora fedora gnome 9y ago Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly e…
CVE-2017-5581 critical 9.8 9.8 FIX slesdebian debian tigervnc 9y ago Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer bound…
CVE-2016-9558 critical 9.8 9.8 FIX arch archdebian debian libdwarf_project 9y ago (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negati…
CVE-2017-6350 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file,…
CVE-2017-6349 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, whic…
CVE-2017-5946 critical 9.8 9.8 FIX debian debian rubyzip_project 9y ago The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "…
CVE-2016-1245 critical 9.8 9.8 slesdebian debian quagga 9y ago It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSI…
CVE-2016-9400 critical 9.8 9.8 FIX fedora fedoradebian debian teeworlds 9y ago The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code…
CVE-2016-9814 critical 9.1 9.1 FIX debian debian simplesamlphp 9y ago The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers …
CVE-2016-10134 critical 9.8 10.0 EXPFIX debian debian zabbix 9y ago SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVE-2016-8859 critical 9.8 9.8 FIX debian debian etalabs 9y ago Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
CVE-2016-2788 critical 9.8 9.8 FIX debian debian puppet 9y ago MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
CVE-2015-8771 critical 9.8 9.8 FIX debian debian gosa_project 9y ago The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
CVE-2017-5953 critical 9.8 9.8 FIX arch arch slesdebian debian vim 9y ago vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer over…
CVE-2016-2148 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu busybox 9y ago Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-10192 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failur…
CVE-2016-10191 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by levera…
CVE-2016-10190 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a nega…
CVE-2016-2403 critical 9.8 9.8 FIX debian debian sensiolabs 10y ago Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CVE-2016-6199 critical 9.8 9.8 FIX debian debian gradle 10y ago ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
CVE-2016-6175 critical 9.8 10.0 EXPFIX debian debian php-gettext_project 10y ago Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
CVE-2015-8608 critical 9.8 9.8 FIX debian debian perl 10y ago The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive lette…
CVE-2016-7447 critical 9.8 9.8 FIX slesdebian debiansuse suse graphicsmagick 10y ago Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2016-7446 critical 9.8 9.8 FIX slesdebian debiansuse suse graphicsmagick 10y ago Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete…
CVE-2016-10150 critical 9.8 9.8 FIX slesdebian debian linux-kernel 10y ago Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or poss…
CVE-2016-10164 critical 9.8 9.8 FIX slesdebian debian x.org 10y ago Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or e…
CVE-2017-5611 critical 9.8 9.8 FIX debian debian wordpressoracle 10y ago SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected…
CVE-2017-5486 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
CVE-2017-5485 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in addrtoname.c:lookup_nsap().
CVE-2017-5484 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:sig_print().
CVE-2017-5483 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The SNMP parser in tcpdump before 4.9.0 has a buffer overflow in print-snmp.c:asn1_parse().
CVE-2017-5482 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2016-8575.
CVE-2017-5342 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().
CVE-2017-5341 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().
CVE-2017-5205 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
CVE-2017-5204 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
CVE-2017-5203 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
CVE-2017-5202 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
CVE-2016-8575 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Q.933 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:q933_print(), a different vulnerability than CVE-2017-5482.
CVE-2016-8574 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The FRF.15 parser in tcpdump before 4.9.0 has a buffer overflow in print-fr.c:frf15_print().
CVE-2016-7993 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM).
CVE-2016-7992 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().
CVE-2016-7986 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.
CVE-2016-7985 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().
CVE-2016-7984 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().
CVE-2016-7983 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
CVE-2016-7975 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
CVE-2016-7974 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.
CVE-2016-7973 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.
CVE-2016-7940 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions.
CVE-2016-7939 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions.
CVE-2016-7938 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame().
CVE-2016-7937 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print().
CVE-2016-7936 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print().
CVE-2016-7935 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print().
CVE-2016-7934 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print().
CVE-2016-7933 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print().
CVE-2016-7932 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum().
CVE-2016-7931 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The MPLS parser in tcpdump before 4.9.0 has a buffer overflow in print-mpls.c:mpls_print().
CVE-2016-7930 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The LLC/SNAP parser in tcpdump before 4.9.0 has a buffer overflow in print-llc.c:llc_print().
CVE-2016-7929 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Juniper PPPoE ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-juniper.c:juniper_parse_header().
CVE-2016-7928 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The IPComp parser in tcpdump before 4.9.0 has a buffer overflow in print-ipcomp.c:ipcomp_print().
CVE-2016-7927 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The IEEE 802.11 parser in tcpdump before 4.9.0 has a buffer overflow in print-802_11.c:ieee802_11_radio_print().
CVE-2016-7926 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The Ethernet parser in tcpdump before 4.9.0 has a buffer overflow in print-ether.c:ethertype_print().
CVE-2016-7925 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The compressed SLIP parser in tcpdump before 4.9.0 has a buffer overflow in print-sl.c:sl_if_print().
CVE-2016-7924 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:oam_print().
CVE-2016-7923 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print().
CVE-2016-7922 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The AH parser in tcpdump before 4.9.0 has a buffer overflow in print-ah.c:ah_print().
CVE-2017-3289 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily …
CVE-2017-3272 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111…
CVE-2017-3241 critical 9.0 10.0 EXPFIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u…
CVE-2016-9636 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-9635 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-9634 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-6912 critical 9.8 9.8 FIX slesdebian debian libgd 10y ago Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
CVE-2016-10160 critical 9.8 9.8 slesdebian debian phpnetapp 10y ago Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possib…
CVE-2016-7036 critical 9.8 9.8 FIX debian debian python-jose_project 10y ago python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
CVE-2016-6223 critical 9.1 9.1 FIX slesarch archdebian debian libtiff 10y ago The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a …
CVE-2016-6164 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors …
CVE-2016-5873 critical 9.8 9.8 FIX debian debian php 10y ago Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.
CVE-2016-3177 critical 9.8 9.8 FIX debian debian giflib_project 10y ago Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
CVE-2015-8972 critical 9.8 9.8 FIX debian debian gnu 10y ago Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large inp…
CVE-2017-5545 critical 9.1 9.1 FIX arch arch slesdebian debian libimobiledevice 10y ago The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via App…
CVE-2016-7794 critical 9.8 9.8 FIX debian debian sociomantic 10y ago sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository name.
CVE-2016-9584 critical 9.1 9.1 FIX slesdebian debian libical_project 10y ago libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.
CVE-2016-7996 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 10y ago Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
CVE-2016-2090 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu freedesktop 10y ago Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-10141 critical 9.8 9.8 FIX debian debian artifex 10y ago An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expres…
CVE-2017-5209 critical 9.1 9.1 FIX arch arch slesdebian debian libimobiledevice 10y ago The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) vi…
CVE-2016-6830 critical 9.8 9.8 FIX debian debian call-cc 10y ago The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-s…
CVE-2016-8705 critical 9.8 9.8 FIX slesarch archdebian debian memcached 10y ago Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and le…
CVE-2016-8704 critical 9.8 9.8 FIX arch arch slesdebian debian memcached 10y ago An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow a…
CVE-2016-8670 critical 9.8 9.8 FIX slesarch archdebian debian libgdphp 10y ago Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers …
CVE-2014-9911 critical 9.8 9.8 FIX slesdebian debian icu-project 10y ago Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a den…
CVE-2016-9942 critical 9.8 9.8 FIX arch arch slesdebian debian libvncserver_project 10y ago Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a cra…