Show filters
92 Total Results
Displaying 31-40 of 92
Sort by:
Attacker Value
Unknown

CVE-2014-3462

Disclosure Date: August 07, 2017 (last updated November 26, 2024)
The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".
Attacker Value
Unknown

CVE-2015-5203

Disclosure Date: August 02, 2017 (last updated November 08, 2023)
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
0
Attacker Value
Unknown

CVE-2015-5221

Disclosure Date: July 25, 2017 (last updated November 08, 2023)
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
0
Attacker Value
Unknown

CVE-2015-5219

Disclosure Date: July 21, 2017 (last updated November 26, 2024)
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
Attacker Value
Unknown

CVE-2017-8932

Disclosure Date: July 06, 2017 (last updated November 08, 2023)
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.
0
Attacker Value
Unknown

CVE-2017-1000366

Disclosure Date: June 19, 2017 (last updated November 26, 2024)
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploitable, as such they have not been given a CVE. This affects glibc 2.25 and earlier.
0
Attacker Value
Unknown

CVE-2016-9960

Disclosure Date: June 06, 2017 (last updated November 08, 2023)
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
0
Attacker Value
Unknown

CVE-2016-9961

Disclosure Date: June 06, 2017 (last updated November 08, 2023)
game-music-emu before 0.6.1 mishandles unspecified integer values.
0
Attacker Value
Unknown

CVE-2016-9842

Disclosure Date: May 23, 2017 (last updated August 29, 2024)
The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
Attacker Value
Unknown

CVE-2016-9840

Disclosure Date: May 23, 2017 (last updated November 08, 2023)
inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.