Show filters
201 Total Results
Displaying 41-50 of 201
Sort by:
Attacker Value
Unknown

CVE-2015-1838

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
0
Attacker Value
Unknown

CVE-2015-1839

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
0
Attacker Value
Unknown

CVE-2016-8884

Disclosure Date: March 28, 2017 (last updated November 08, 2023)
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.
0
Attacker Value
Unknown

CVE-2016-9243

Disclosure Date: March 27, 2017 (last updated September 10, 2024)
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
Attacker Value
Unknown

CVE-2016-8887

Disclosure Date: March 23, 2017 (last updated November 08, 2023)
The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).
0
Attacker Value
Unknown

CVE-2016-7972

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7970

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-7969

Disclosure Date: March 03, 2017 (last updated November 08, 2023)
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
Attacker Value
Unknown

CVE-2016-9400

Disclosure Date: February 22, 2017 (last updated November 08, 2023)
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
Attacker Value
Unknown

CVE-2016-6233

Disclosure Date: February 17, 2017 (last updated November 08, 2023)
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
0