Show filters
351 Total Results
Displaying 41-50 of 351
Sort by:
Attacker Value
Unknown

CVE-2015-8924

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
0
Attacker Value
Unknown

CVE-2015-8922

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
0
Attacker Value
Unknown

CVE-2015-8928

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
0
Attacker Value
Unknown

CVE-2015-8930

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.
0
Attacker Value
Unknown

CVE-2015-8934

Disclosure Date: September 20, 2016 (last updated November 25, 2024)
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
0
Attacker Value
Unknown

CVE-2016-6128

Disclosure Date: August 07, 2016 (last updated November 25, 2024)
The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.
Attacker Value
Unknown

CVE-2016-6232

Disclosure Date: August 02, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
0
Attacker Value
Unknown

CVE-2015-8946

Disclosure Date: July 22, 2016 (last updated November 25, 2024)
ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-6224

Disclosure Date: July 22, 2016 (last updated November 08, 2023)
ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.
0
Attacker Value
Unknown

CVE-2016-3615

Disclosure Date: July 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.
0