Show filters
135 Total Results
Displaying 21-30 of 135
Sort by:
Attacker Value
Unknown

CVE-2014-8241

Disclosure Date: December 14, 2016 (last updated November 25, 2024)
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
0
Attacker Value
Unknown

CVE-2016-7796

Disclosure Date: October 13, 2016 (last updated November 25, 2024)
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
0
Attacker Value
Unknown

CVE-2016-4300

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-5418

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
0
Attacker Value
Unknown

CVE-2016-4302

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
0
Attacker Value
Unknown

CVE-2016-7166

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
0
Attacker Value
Unknown

CVE-2016-5844

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
0
Attacker Value
Unknown

CVE-2016-4809

Disclosure Date: September 21, 2016 (last updated November 25, 2024)
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
0
Attacker Value
Unknown

CVE-2016-5388

Disclosure Date: July 19, 2016 (last updated November 25, 2024)
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.
0
Attacker Value
Unknown

CVE-2016-0758

Disclosure Date: June 27, 2016 (last updated November 25, 2024)
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.