Show filters
117 Total Results
Displaying 41-50 of 117
Sort by:
Attacker Value
Unknown

CVE-2016-4796

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
0
Attacker Value
Unknown

CVE-2016-9085

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Attacker Value
Unknown

CVE-2016-8568

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
0
Attacker Value
Unknown

CVE-2016-9108

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
Attacker Value
Unknown

CVE-2016-8569

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
0
Attacker Value
Unknown

CVE-2016-7543

Disclosure Date: January 19, 2017 (last updated November 08, 2023)
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
0
Attacker Value
Unknown

CVE-2016-2090

Disclosure Date: January 13, 2017 (last updated November 08, 2023)
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2016-8606

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
0
Attacker Value
Unknown

CVE-2016-8605

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
0
Attacker Value
Unknown

CVE-2016-2334

Disclosure Date: December 13, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
0