Show filters
1,398 Total Results
Displaying 141-150 of 1,398
Sort by:
Attacker Value
Unknown
CVE-2015-8923
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
0
Attacker Value
Unknown
CVE-2015-8921
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
0
Attacker Value
Unknown
CVE-2015-8924
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
0
Attacker Value
Unknown
CVE-2015-8920
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
0
Attacker Value
Unknown
CVE-2015-8922
Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
0
Attacker Value
Unknown
CVE-2015-8948
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2016-6262
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
0
Attacker Value
Unknown
CVE-2016-6855
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
0
Attacker Value
Unknown
CVE-2016-5421
Disclosure Date: August 10, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-5772
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.
0