Show filters
117 Total Results
Displaying 31-40 of 117
Sort by:
Attacker Value
Unknown

CVE-2017-5849

Disclosure Date: March 15, 2017 (last updated November 08, 2023)
tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
0
Attacker Value
Unknown

CVE-2016-7972

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7970

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7969

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
Attacker Value
Unknown

CVE-2016-9956

Disclosure Date: February 22, 2017 (last updated November 08, 2023)
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
0
Attacker Value
Unknown

CVE-2016-6233

Disclosure Date: February 17, 2017 (last updated November 08, 2023)
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
0
Attacker Value
Unknown

CVE-2016-4861

Disclosure Date: February 17, 2017 (last updated November 08, 2023)
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
0
Attacker Value
Unknown

CVE-2016-6866

Disclosure Date: February 15, 2017 (last updated November 08, 2023)
slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.
0
Attacker Value
Unknown

CVE-2013-7459

Disclosure Date: February 15, 2017 (last updated November 08, 2023)
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.
0
Attacker Value
Unknown

CVE-2016-4797

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
0