Search

Found 17,057 results in 806ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-5645 critical 9.8 9.8 FIX debian debian sles rhel apachenetappredhat 9y ago Deserialization of Untrusted Data in Log4j
CVE-2017-5651 critical 9.8 9.8 FIX slesdebian debian apache 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, …
CVE-2017-5648 critical 9.1 9.1 FIX slesdebian debian apache 9y ago While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use th…
CVE-2017-7882 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
CVE-2017-7875 critical 9.8 9.8 FIX debian debian feh_project 9y ago In wallpaper.c in feh before v2.18.3, if a malicious client pretends to be the E17 window manager, it is possible to trigger an out-of-boundary heap write while receiving an IPC message. An integer o…
CVE-2017-7870 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
CVE-2017-7866 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.
CVE-2017-7865 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align…
CVE-2017-7864 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
CVE-2017-7863 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.
CVE-2017-7862 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.
CVE-2017-7861 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
CVE-2017-7860 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.
CVE-2017-7859 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
CVE-2017-7858 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
CVE-2017-7857 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfob…
CVE-2017-7856 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
CVE-2016-10328 critical 9.8 9.8 FIX slesarch archdebian debian freetypeoracle 9y ago FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
CVE-2016-10327 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.
CVE-2016-10324 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.
CVE-2016-4800 critical 9.8 9.8 FIX debian debian eclipse 9y ago Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
CVE-2015-8271 critical 9.8 9.8 FIX debian debian rtmpdump_project 9y ago The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
CVE-2015-6674 critical 9.8 9.8 FIX debian debian inspircd 9y ago Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplet…
CVE-2016-6808 critical 9.8 9.8 FIX debian debian apache 9y ago Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-1908 critical 9.8 9.8 FIX slesdebian debian rhel openbsd 9y ago The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to t…
CVE-2017-7239 critical 9.8 9.8 FIX debian debian ninka_project 9y ago Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
CVE-2017-7614 critical 9.8 9.8 FIX debian debian sles gnu 9y ago elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote a…
CVE-2017-0561 critical 9.8 10.0 EXPFIX debian debian linux-kernel 9y ago A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due …
CVE-2016-6809 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
CVE-2016-10229 critical 9.8 9.8 FIX slesarch archdebian debian 9y ago udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with …
CVE-2014-5009 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
CVE-2014-5008 critical 9.8 9.8 FIX debian debian snoopyredhat 9y ago Snoopy allows remote attackers to execute arbitrary commands.
CVE-2008-7313 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
CVE-2014-9826 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
CVE-2017-5226 critical 10.0 10.0 FIX debian debian sles rhel projectatomic 9y ago RHSA-2019:1143: flatpak security update (Important)
CVE-2014-6440 critical 9.8 9.8 FIX debian debian videolan 9y ago VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.
CVE-2016-10152 critical 9.8 9.8 FIX debian debian hesiod_project 9y ago The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root …
CVE-2016-9121 critical 9.1 9.1 FIX debian debian go-jose_project 9y ago go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received pu…
CVE-2017-7191 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
CVE-2017-6542 critical 9.8 10.0 EXPFIX suse susedebian debian putty 9y ago The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect…
CVE-2017-5511 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
CVE-2017-5337 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
CVE-2017-5336 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted Op…
CVE-2017-5334 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language in…
CVE-2016-10145 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
CVE-2016-10144 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
CVE-2016-10133 critical 9.8 9.8 FIX debian debian artifex 9y ago Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments …
CVE-2016-10128 critical 9.8 9.8 FIX slesarch archdebian debian libgit2_project 9y ago Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspec…
CVE-2015-8556 critical 10.0 10.0 EXPFIX slesdebian debian qemu 9y ago Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CVE-2015-8626 critical 9.8 9.8 FIX debian debian mediawiki 9y ago The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which ma…
CVE-2015-0855 critical 9.8 9.8 FIX debian debian pitivi 9y ago The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.
CVE-2017-5897 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu 9y ago The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds …
CVE-2017-5206 critical 9.0 9.0 FIX arch archdebian debian linux-kernel firejail_project 9y ago Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
CVE-2017-7226 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses…
CVE-2017-7214 critical 9.8 9.8 FIX slesdebian debian openstack 9y ago An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level lo…
CVE-2014-9939 critical 9.8 9.8 FIX debian debian gnu 9y ago ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
CVE-2015-8954 critical 9.8 9.8 FIX debian debian openinfosecfoundation 9y ago The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafte…
CVE-2014-9847 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu opensuse_projectimagemagick 9y ago The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
CVE-2014-9846 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
CVE-2014-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2014-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
CVE-2016-10253 critical 9.8 9.8 FIX slesdebian debian erlang 9y ago An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly speci…
CVE-2014-9852 critical 9.8 9.8 FIX slesdebian debiansuse suse imagemagick 9y ago distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
CVE-2017-6969 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak a…
CVE-2015-8981 critical 9.8 9.8 FIX slesdebian debian podofo_project 9y ago Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.
CVE-2016-5239 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
CVE-2017-5522 critical 9.8 9.8 FIX debian debian osgeo 9y ago Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary…
CVE-2016-10195 critical 9.8 9.8 FIX slesdebian debian libevent_project 9y ago The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack…
CVE-2016-10166 critical 9.8 9.8 FIX slesdebian debian libgd 9y ago Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors relate…
CVE-2017-5668 critical 9.8 9.8 FIX debian debian bitlbee 9y ago bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact …
CVE-2016-10188 critical 9.8 9.8 FIX debian debian bitlbee 9y ago Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to exp…
CVE-2017-5929 critical 9.8 9.8 FIX debian debian qosredhat 9y ago QOS.ch Logback vulnerable to Deserialization of Untrusted Data
CVE-2016-4658 critical 9.8 9.8 FIX slesarch archdebian debian xmlsoft 9y ago xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, wh…
CVE-2016-8863 critical 9.8 9.8 debian debian libupnp_project 9y ago Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possi…
CVE-2016-7407 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
CVE-2016-7406 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
CVE-2016-10204 critical 9.8 9.8 FIX debian debian zoneminder 9y ago SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.
CVE-2016-10127 critical 9.0 9.0 slesdebian debian pysaml2_project 9y ago PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.
CVE-2017-5885 critical 9.8 9.8 FIX slesdebian debianfedora fedora gnome 9y ago Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly e…
CVE-2017-5581 critical 9.8 9.8 FIX slesdebian debian tigervnc 9y ago Buffer overflow in the ModifiablePixelBuffer::fillRect function in TigerVNC before 1.7.1 allows remote servers to execute arbitrary code via an RRE message with subrectangle outside framebuffer bound…
CVE-2016-9558 critical 9.8 9.8 FIX arch archdebian debian libdwarf_project 9y ago (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negati…
CVE-2017-6350 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file,…
CVE-2017-6349 critical 9.8 9.8 FIX slesdebian debian vim 9y ago An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, whic…
CVE-2017-5946 critical 9.8 9.8 FIX debian debian rubyzip_project 9y ago The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "…
CVE-2016-1245 critical 9.8 9.8 slesdebian debian quagga 9y ago It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSI…
CVE-2016-9400 critical 9.8 9.8 FIX fedora fedoradebian debian teeworlds 9y ago The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code…
CVE-2016-9814 critical 9.1 9.1 FIX debian debian simplesamlphp 9y ago The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers …
CVE-2016-10134 critical 9.8 10.0 EXPFIX debian debian zabbix 9y ago SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
CVE-2016-8859 critical 9.8 9.8 FIX debian debian etalabs 9y ago Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, which triggers an out-of-bounds write.
CVE-2016-2788 critical 9.8 9.8 FIX debian debian puppet 9y ago MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.
CVE-2015-8771 critical 9.8 9.8 FIX debian debian gosa_project 9y ago The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
CVE-2017-5953 critical 9.8 9.8 FIX arch arch slesdebian debian vim 9y ago vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer over…
CVE-2016-2148 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu busybox 10y ago Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-10192 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failur…
CVE-2016-10191 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by levera…
CVE-2016-10190 critical 9.8 9.8 FIX debian debian ffmpeg 10y ago Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a nega…
CVE-2016-2403 critical 9.8 9.8 FIX debian debian sensiolabs 10y ago Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
CVE-2016-6199 critical 9.8 9.8 FIX debian debian gradle 10y ago ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
CVE-2016-6175 critical 9.8 10.0 EXPFIX debian debian php-gettext_project 10y ago Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
CVE-2015-8608 critical 9.8 9.8 FIX debian debian perl 10y ago The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly execute arbitrary code via a crafted (1) drive lette…