Search

Found 3,839 results in 1611ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-7993 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago A bug in util-print.c:relts_print() in tcpdump before 4.9.0 could cause a buffer overflow in multiple protocol parsers (DNS, DVMRP, HSRP, IGMP, lightweight resolver protocol, PIM).
CVE-2016-7992 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().
CVE-2016-7986 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.
CVE-2016-7985 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().
CVE-2016-7984 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().
CVE-2016-7983 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
CVE-2016-7975 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().
CVE-2016-7974 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.
CVE-2016-7973 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.
CVE-2016-7940 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The STP parser in tcpdump before 4.9.0 has a buffer overflow in print-stp.c, multiple functions.
CVE-2016-7939 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The GRE parser in tcpdump before 4.9.0 has a buffer overflow in print-gre.c, multiple functions.
CVE-2016-7938 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame().
CVE-2016-7937 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The VAT parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:vat_print().
CVE-2016-7936 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The UDP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:udp_print().
CVE-2016-7935 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print().
CVE-2016-7934 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The RTCP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtcp_print().
CVE-2016-7933 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The PPP parser in tcpdump before 4.9.0 has a buffer overflow in print-ppp.c:ppp_hdlc_if_print().
CVE-2016-7932 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The PIM parser in tcpdump before 4.9.0 has a buffer overflow in print-pim.c:pimv2_check_checksum().
CVE-2016-7931 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The MPLS parser in tcpdump before 4.9.0 has a buffer overflow in print-mpls.c:mpls_print().
CVE-2016-7930 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The LLC/SNAP parser in tcpdump before 4.9.0 has a buffer overflow in print-llc.c:llc_print().
CVE-2016-7929 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The Juniper PPPoE ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-juniper.c:juniper_parse_header().
CVE-2016-7928 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The IPComp parser in tcpdump before 4.9.0 has a buffer overflow in print-ipcomp.c:ipcomp_print().
CVE-2016-7927 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The IEEE 802.11 parser in tcpdump before 4.9.0 has a buffer overflow in print-802_11.c:ieee802_11_radio_print().
CVE-2016-7926 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The Ethernet parser in tcpdump before 4.9.0 has a buffer overflow in print-ether.c:ethertype_print().
CVE-2016-7925 critical 9.8 9.8 FIX arch arch slesdebian debian tcpdump 10y ago The compressed SLIP parser in tcpdump before 4.9.0 has a buffer overflow in print-sl.c:sl_if_print().
CVE-2016-7924 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-atm.c:oam_print().
CVE-2016-7923 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print().
CVE-2016-7922 critical 9.8 9.8 FIX slesarch archdebian debian tcpdump 10y ago The AH parser in tcpdump before 4.9.0 has a buffer overflow in print-ah.c:ah_print().
CVE-2017-3289 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111. Easily …
CVE-2017-3272 critical 9.6 9.6 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111…
CVE-2017-3259 low 3.7 3.7 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112. Difficult to exploit vulnerability allow…
CVE-2017-3241 critical 9.0 10.0 EXPFIX slesdebian debian oracle 10y ago Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u…
CVE-2016-9636 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-9635 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-9634 critical 9.8 9.8 FIX slesdebian debian rhel gstreamer 10y ago Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a deni…
CVE-2016-8328 low 3.7 3.7 FIX slesdebian debian oracle 10y ago Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version that is affected is Java SE: 8u112. Difficult to exploit vulnerability allows unau…
CVE-2016-1551 low 3.7 3.7 FIX slesdebian debian ntpntpsec 10y ago ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference cloc…
CVE-2016-9932 low 3.3 3.3 FIX slesdebian debian 10y ago CMPXCHG8B emulation in Xen 3.3.x through 4.7.x on x86 systems allows local HVM guest OS users to obtain sensitive information from host stack memory via a "supposedly-ignored" operand size prefix.
CVE-2016-6912 critical 9.8 9.8 FIX slesdebian debian libgd 10y ago Double free vulnerability in the gdImageWebPtr function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via large width and height values.
CVE-2016-10160 critical 9.8 9.8 slesdebian debian phpnetapp 10y ago Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possib…
CVE-2016-7036 critical 9.8 9.8 FIX debian debian python-jose_project 10y ago python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
CVE-2016-6223 critical 9.1 9.1 FIX slesarch archdebian debian libtiff 10y ago The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a …
CVE-2016-6164 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote attackers to have unspecified impact via vectors …
CVE-2016-5873 critical 9.8 9.8 FIX debian debian php 10y ago Buffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via non-printable characters in a URL.
CVE-2016-3177 critical 9.8 9.8 FIX debian debian giflib_project 10y ago Multiple use-after-free and double-free vulnerabilities in gifcolor.c in GIFLIB 5.1.2 have unspecified impact and attack vectors.
CVE-2015-8972 critical 9.8 9.8 FIX debian debian gnu 10y ago Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large inp…
CVE-2017-5545 critical 9.1 9.1 FIX arch arch slesdebian debian libimobiledevice 10y ago The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via App…
CVE-2016-7794 critical 9.8 9.8 FIX debian debian sociomantic 10y ago sociomantic-tsunami git-hub before 0.10.3 allows remote attackers to execute arbitrary code via a crafted repository name.
CVE-2016-9584 critical 9.1 9.1 FIX slesdebian debian libical_project 10y ago libical allows remote attackers to cause a denial of service (use-after-free) and possibly read heap memory via a crafted ics file.
CVE-2016-7996 critical 9.8 9.8 FIX slesdebian debian graphicsmagick 10y ago Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
CVE-2016-7429 low 3.7 3.7 FIX slesarch archdebian debian ntp 10y ago NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source)…
CVE-2016-2090 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu freedesktop 10y ago Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-10141 critical 9.8 9.8 FIX debian debian artifex 10y ago An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb860f4fcd4b2045. The attack requires a regular expres…
CVE-2017-5209 critical 9.1 9.1 FIX arch arch slesdebian debian libimobiledevice 10y ago The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) vi…
CVE-2016-9015 low 3.7 3.7 FIX slesdebian debian python 10y ago Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the l…
CVE-2016-6830 critical 9.8 9.8 FIX debian debian call-cc 10y ago The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-s…
CVE-2016-8705 critical 9.8 9.8 FIX slesarch archdebian debian memcached 10y ago Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and le…
CVE-2016-8704 critical 9.8 9.8 FIX arch arch slesdebian debian memcached 10y ago An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow a…
CVE-2016-4323 low 3.7 3.7 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or …
CVE-2016-2380 low 3.1 3.1 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced …
CVE-2016-8670 critical 9.8 9.8 FIX slesarch archdebian debian libgdphp 10y ago Integer signedness error in the dynamicGetbuf function in gd_io_dp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers …
CVE-2014-9911 critical 9.8 9.8 FIX slesdebian debian icu-project 10y ago Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a den…
CVE-2016-9942 critical 9.8 9.8 FIX arch arch slesdebian debian libvncserver_project 10y ago Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a cra…
CVE-2016-9941 critical 9.8 9.8 FIX arch arch slesdebian debian libvncserver_project 10y ago Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a …
CVE-2016-10074 critical 9.8 10.0 EXPFIX debian debian swiftmailer 10y ago Swift Mailer mail transport Command Injection
CVE-2016-10045 critical 9.8 10.0 EXPFIX arch archdebian debian phpmailer_projectwordpressjoomla 10y ago Remote code execution in PHPMailer
CVE-2016-9877 critical 9.8 9.8 FIX slesdebian debian broadcompivotal_software 10y ago An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport…
CVE-2016-9908 low 3.3 3.3 FIX slesdebian debian qemu 10y ago Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest use…
CVE-2016-9180 critical 9.1 9.1 FIX slesdebian debian xmltwig 10y ago perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's …
CVE-2013-1430 critical 9.8 9.8 FIX slesdebian debian neutrinolabs 10y ago An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the u…
CVE-2014-8241 critical 9.8 9.8 FIX rheldebian debian tigervnc 10y ago XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
CVE-2016-7953 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
CVE-2016-7951 critical 9.8 9.8 FIX slesdebian debianfedora fedora x 10y ago Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.
CVE-2016-7950 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
CVE-2016-7949 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors …
CVE-2016-7948 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
CVE-2016-7947 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.
CVE-2016-7944 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and …
CVE-2016-7943 critical 9.8 9.8 FIX debian debianfedora fedora x.org 10y ago The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.
CVE-2016-7942 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.
CVE-2016-5407 critical 9.8 9.8 FIX slesdebian debianfedora fedora x.org 10y ago The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifica…
CVE-2015-5073 critical 9.1 9.1 FIX debian debian ibmpcre 10y ago Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from hea…
CVE-2015-3210 critical 9.8 9.8 FIX debian debian pcre 10y ago Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)…
CVE-2016-6520 critical 9.1 9.1 FIX slesdebian debian imagemagick 10y ago Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.
CVE-2016-5841 critical 9.8 9.8 FIX slesdebian debian imagemagick 10y ago Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involvi…
CVE-2016-5691 critical 9.8 9.8 FIX slesdebian debian imagemagick 10y ago The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixe…
CVE-2016-5690 critical 9.8 9.8 FIX slesdebian debian imagemagick 10y ago The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing th…
CVE-2016-5689 critical 9.8 9.8 FIX slesdebian debian imagemagick 10y ago The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL pointer checks.
CVE-2016-5687 critical 9.8 9.8 FIX slesdebian debian imagemagick 10y ago The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-b…
CVE-2016-9427 critical 9.8 9.8 FIX slesdebian debiansuse suse bdwgc_project 10y ago Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocat…
CVE-2016-9866 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. When the arg_separator is different from its default & value, the CSRF token was not properly stripped from the return URL of the preference import action. All …
CVE-2016-9865 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.…
CVE-2016-9849 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username by using Null Byte in the username. All 4.6.x vers…
CVE-2016-6629 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by A…
CVE-2016-6620 critical 9.8 9.8 FIX debian debian phpmyadmin 10y ago An issue was discovered in phpMyAdmin. Some data is passed to the PHP unserialize() function without verification that it's valid serialized data. The unserialization can result in code execution bec…
CVE-2016-9013 critical 9.8 9.8 FIX slesarch archubuntu ubuntu djangoproject 10y ago Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it eas…
CVE-2016-9480 critical 9.1 9.1 FIX arch archdebian debian libdwarf_project 10y ago libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" …
CVE-2016-9555 critical 9.8 9.8 FIX slesdebian debian linux-kernel 10y ago The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-…
CVE-2016-9540 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiffcp.c in libtiff 4.0.6 has an out-of-bounds write on tiled images with odd tile width versus image width. Reported as MSVR 35103, aka "cpStripToTile heap-buffer-overflow."
CVE-2016-9539 critical 9.8 9.8 FIX arch arch slesdebian debian libtiff 10y ago tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.