Show filters
252 Total Results
Displaying 181-190 of 252
Sort by:
Attacker Value
Unknown

CVE-2016-0718

Disclosure Date: May 26, 2016 (last updated November 25, 2024)
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
Attacker Value
Unknown

CVE-2015-8863

Disclosure Date: May 06, 2016 (last updated November 25, 2024)
Off-by-one error in the tokenadd function in jv_parse.c in jq allows remote attackers to cause a denial of service (crash) via a long JSON-encoded number, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-3977

Disclosure Date: April 21, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.
0
Attacker Value
Unknown

CVE-2016-3982

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2015-7545

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.
0
Attacker Value
Unknown

CVE-2015-8805

Disclosure Date: February 23, 2016 (last updated November 25, 2024)
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.
0
Attacker Value
Unknown

CVE-2015-8803

Disclosure Date: February 23, 2016 (last updated November 25, 2024)
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.
0
Attacker Value
Unknown

CVE-2015-8804

Disclosure Date: February 23, 2016 (last updated November 25, 2024)
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-7758

Disclosure Date: January 08, 2016 (last updated November 25, 2024)
Gummi 0.6.5 allows local users to write to arbitrary files via a symlink attack on a temporary dot file that uses the name of an existing file and a (1) .aux, (2) .log, (3) .out, (4) .pdf, or (5) .toc extension for the file name, as demonstrated by .thesis.tex.aux.
0
Attacker Value
Unknown

CVE-2014-9756

Disclosure Date: November 19, 2015 (last updated October 05, 2023)
The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.
0