Search

Found 2,415 results in 953ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-9053 critical 9.1 9.1 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in …
CVE-2017-9052 critical 9.8 9.8 FIX slesdebian debian libdwarf_project 9y ago An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few pl…
CVE-2017-9051 critical 9.8 9.8 FIX debian debian libav 9y ago libav before 12.1 is vulnerable to an invalid read of size 1 due to NULL pointer dereferencing in the nsv_read_chunk function in libavformat/nsvdec.c.
CVE-2017-9031 critical 9.8 9.8 FIX debian debian deluge-torrent 9y ago The WebUI component in Deluge before 1.3.15 contains a directory traversal vulnerability involving a request in which the name of the render file is not associated with any template file.
CVE-2017-6886 critical 9.8 9.8 FIX slesdebian debian libraw 9y ago An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be exploited to corrupt memory.
CVE-2017-8911 critical 9.8 9.8 FIX debian debian tnef_project 9y ago An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid write operations, controlled by an attacker.
CVE-2017-8798 critical 9.8 10.0 EXPFIX arch archdebian debian miniupnp_project 9y ago Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-5461 critical 9.8 9.8 FIX arch arch slesdebian debian mozilla 9y ago Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of…
CVE-2017-8872 critical 9.1 9.1 FIX slesdebian debian xmlsoft 9y ago The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure.
CVE-2017-8786 critical 9.8 9.8 FIX slesdebian debian pcre 9y ago pcre2test.c in PCRE2 10.23 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression.
CVE-2017-7476 critical 9.8 9.8 FIX slesdebian debian gnulib 9y ago Gnulib before 2017-04-26 has a heap-based buffer overflow with the TZ environment variable. The error is in the save_abbr function in time_rz.c.
CVE-2016-10243 critical 9.8 9.8 FIX slesdebian debianfedora fedora tug 9y ago TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
CVE-2017-8399 critical 9.8 9.8 FIX debian debian pcre 9y ago PCRE2 before 10.30 has an out-of-bounds write caused by a stack-based buffer overflow in pcre2_match.c, related to a "pattern with very many captures."
CVE-2016-8649 critical 9.1 9.1 FIX slesdebian debian linuxcontainers 9y ago lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's f…
CVE-2017-8378 critical 9.8 9.8 FIX slesdebian debian podofo_project 9y ago Heap-based buffer overflow in the PdfParser::ReadObjects function in base/PdfParser.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspe…
CVE-2017-6519 critical 9.1 9.1 FIX debian debian slesubuntu ubuntu avahi 9y ago avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (tra…
CVE-2017-8366 critical 9.8 9.8 FIX arch archdebian debian ettercap_project 9y ago The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other imp…
CVE-2017-8359 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-03-29 has an out-of-bounds write caused by a heap-based use-after-free related to the grpc_call_destroy function in core/lib/surface/call.c.
CVE-2017-8358 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.
CVE-2017-7895 critical 9.8 9.8 FIX slesdebian debian linux-kernel 9y ago The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buffer, which allows remote attackers to trigger pointer-arithmetic errors or possi…
CVE-2017-8305 critical 9.8 9.8 FIX debian debian 13thmonkey 9y ago The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy.
CVE-2017-8287 critical 9.8 9.8 FIX arch arch slesdebian debian freetype 9y ago FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder_close_contour function in psaux/psobjs.c.
CVE-2017-8283 critical 9.8 9.8 FIX debian debian debian 9y ago dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct dire…
CVE-2017-8105 critical 9.8 9.8 FIX arch arch slesdebian debian freetype 9y ago FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function in psaux/t1decode.c.
CVE-2014-9654 critical 9.8 9.8 FIX debian debian googleicu-project 9y ago The Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.91, calculates certain values without ensuring tha…
CVE-2017-5645 critical 9.8 9.8 FIX debian debian sles rhel apachenetappredhat 9y ago Deserialization of Untrusted Data in Log4j
CVE-2017-5651 critical 9.8 9.8 FIX slesdebian debian apache 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, …
CVE-2017-5648 critical 9.1 9.1 FIX slesdebian debian apache 9y ago While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use th…
CVE-2017-7882 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
CVE-2017-7875 critical 9.8 9.8 FIX debian debian feh_project 9y ago In wallpaper.c in feh before v2.18.3, if a malicious client pretends to be the E17 window manager, it is possible to trigger an out-of-boundary heap write while receiving an IPC message. An integer o…
CVE-2017-7870 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
CVE-2017-7866 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-23 has an out-of-bounds write caused by a stack-based buffer overflow related to the decode_zbuf function in libavcodec/pngdec.c.
CVE-2017-7865 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in libavcodec/interplayvideo.c and the avcodec_align…
CVE-2017-7864 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-02-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tt_size_reset function in truetype/ttobjs.c.
CVE-2017-7863 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/pngdec.c.
CVE-2017-7862 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-02-07 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame function in libavcodec/pictordec.c.
CVE-2017-7861 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-02-22 has an out-of-bounds write related to the gpr_free function in core/lib/support/alloc.c.
CVE-2017-7860 critical 9.8 9.8 FIX debian debian grpc 9y ago Google gRPC before 2017-02-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the parse_unix function in core/ext/client_channel/parse_address.c.
CVE-2017-7859 critical 9.8 9.8 FIX debian debian ffmpeg 9y ago FFmpeg before 2017-03-05 has an out-of-bounds write caused by a heap-based buffer overflow related to the ff_h264_slice_context_init function in libavcodec/h264dec.c.
CVE-2017-7858 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-03-07 has an out-of-bounds write related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfobjs.c.
CVE-2017-7857 critical 9.8 9.8 FIX slesdebian debian freetype 9y ago FreeType 2 before 2017-03-08 has an out-of-bounds write caused by a heap-based buffer overflow related to the TT_Get_MM_Var function in truetype/ttgxvar.c and the sfnt_init_face function in sfnt/sfob…
CVE-2017-7856 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
CVE-2016-10328 critical 9.8 9.8 FIX slesarch archdebian debian freetypeoracle 9y ago FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.
CVE-2016-10327 critical 9.8 9.8 FIX slesdebian debian libreoffice 9y ago LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.
CVE-2016-10324 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.
CVE-2016-4800 critical 9.8 9.8 FIX debian debian eclipse 9y ago Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request
CVE-2015-8271 critical 9.8 9.8 FIX debian debian rtmpdump_project 9y ago The AMF3CD_AddProp function in amf.c in RTMPDump 2.4 allows remote RTMP Media servers to execute arbitrary code.
CVE-2015-6674 critical 9.8 9.8 FIX debian debian inspircd 9y ago Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplet…
CVE-2016-6808 critical 9.8 9.8 FIX debian debian apache 9y ago Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-1908 critical 9.8 9.8 FIX slesdebian debian rhel openbsd 9y ago The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to t…
CVE-2017-7239 critical 9.8 9.8 FIX debian debian ninka_project 9y ago Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.
CVE-2017-7614 critical 9.8 9.8 FIX debian debian sles gnu 9y ago elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote a…
CVE-2017-0561 critical 9.8 10.0 EXPFIX debian debian linux-kernel 9y ago A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due …
CVE-2016-6809 critical 9.8 9.8 FIX debian debian apache 9y ago Apache Tika allows Java code execution for serialized objects embedded in MATLAB files
CVE-2016-10229 critical 9.8 9.8 FIX slesarch archdebian debian 9y ago udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with …
CVE-2014-5009 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
CVE-2014-5008 critical 9.8 9.8 FIX debian debian snoopyredhat 9y ago Snoopy allows remote attackers to execute arbitrary commands.
CVE-2008-7313 critical 9.8 9.8 FIX debian debian snoopyredhatnagios 9y ago The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
CVE-2014-9826 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago ImageMagick allows remote attackers to have unspecified impact via vectors related to error handling in sun files.
CVE-2017-5226 critical 10.0 10.0 FIX debian debian sles rhel projectatomic 9y ago RHSA-2019:1143: flatpak security update (Important)
CVE-2014-6440 critical 9.8 9.8 FIX debian debian videolan 9y ago VideoLAN VLC media player before 2.1.5 allows remote attackers to execute arbitrary code or cause a denial of service.
CVE-2016-10152 critical 9.8 9.8 FIX debian debian hesiod_project 9y ago The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root …
CVE-2016-9121 critical 9.1 9.1 FIX debian debian go-jose_project 9y ago go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received pu…
CVE-2017-7191 critical 9.8 9.8 FIX arch archdebian debian irssi 9y ago The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.
CVE-2017-6542 critical 9.8 10.0 EXPFIX suse susedebian debian putty 9y ago The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large length value in an agent protocol message and leveraging the ability to connect…
CVE-2017-5511 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer overflow.
CVE-2017-5337 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
CVE-2017-5336 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted Op…
CVE-2017-5334 critical 9.8 9.8 FIX slesdebian debiansuse suse gnu 9y ago Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language in…
CVE-2016-10145 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.
CVE-2016-10144 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
CVE-2016-10133 critical 9.8 9.8 FIX debian debian artifex 9y ago Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc. MuJS allows attackers to have unspecified impact by leveraging an error when dropping extra arguments …
CVE-2016-10128 critical 9.8 9.8 FIX slesarch archdebian debian libgit2_project 9y ago Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspec…
CVE-2015-8556 critical 10.0 10.0 EXPFIX slesdebian debian qemu 9y ago Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
CVE-2015-8626 critical 9.8 9.8 FIX debian debian mediawiki 9y ago The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which ma…
CVE-2015-0855 critical 9.8 9.8 FIX debian debian pitivi 9y ago The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.
CVE-2017-5897 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu 9y ago The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags in an IPv6 packet, which trigger an out-of-bounds …
CVE-2017-5206 critical 9.0 9.0 FIX arch archdebian debian linux-kernel firejail_project 9y ago Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument.
CVE-2017-7226 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses…
CVE-2017-7214 critical 9.8 9.8 FIX slesdebian debian openstack 9y ago An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level lo…
CVE-2014-9939 critical 9.8 9.8 FIX debian debian gnu 9y ago ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
CVE-2015-8954 critical 9.8 9.8 FIX debian debian openinfosecfoundation 9y ago The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafte…
CVE-2014-9847 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu opensuse_projectimagemagick 9y ago The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
CVE-2014-9846 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
CVE-2014-9843 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
CVE-2014-9841 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
CVE-2016-10253 critical 9.8 9.8 FIX slesdebian debian erlang 9y ago An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly speci…
CVE-2014-9852 critical 9.8 9.8 FIX slesdebian debiansuse suse imagemagick 9y ago distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
CVE-2017-6969 critical 9.1 9.1 FIX debian debianarch arch gnu 9y ago readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak a…
CVE-2015-8981 critical 9.8 9.8 FIX slesdebian debian podofo_project 9y ago Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.
CVE-2016-5239 critical 9.8 9.8 FIX slesdebian debian imagemagick 9y ago The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
CVE-2017-5522 critical 9.8 9.8 FIX debian debian osgeo 9y ago Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary…
CVE-2016-10195 critical 9.8 9.8 FIX slesdebian debian libevent_project 9y ago The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_len variable, which triggers an out-of-bounds stack…
CVE-2016-10166 critical 9.8 9.8 FIX slesdebian debian libgd 9y ago Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors relate…
CVE-2017-5668 critical 9.8 9.8 FIX debian debian bitlbee 9y ago bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact …
CVE-2016-10188 critical 9.8 9.8 FIX debian debian bitlbee 9y ago Use-after-free vulnerability in bitlbee-libpurple before 3.5 allows remote servers to cause a denial of service (crash) or possibly execute arbitrary code by causing a file transfer connection to exp…
CVE-2017-5929 critical 9.8 9.8 FIX debian debian qosredhat 9y ago QOS.ch Logback vulnerable to Deserialization of Untrusted Data
CVE-2016-4658 critical 9.8 9.8 FIX slesarch archdebian debian xmlsoft 9y ago Nokogiri does not forbid namespace nodes in XPointer ranges
CVE-2016-8863 critical 9.8 9.8 debian debian libupnp_project 9y ago Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possi…
CVE-2016-7407 critical 9.8 9.8 FIX debian debian dropbear_ssh_project 9y ago The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.