Show filters
75 Total Results
Displaying 61-70 of 75
Sort by:
Attacker Value
Unknown
CVE-2016-7944
Disclosure Date: December 13, 2016 (last updated November 08, 2023)
Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.
0
Attacker Value
Unknown
CVE-2016-7950
Disclosure Date: December 13, 2016 (last updated November 08, 2023)
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
0
Attacker Value
Unknown
CVE-2016-9014
Disclosure Date: December 09, 2016 (last updated November 08, 2023)
Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.
0
Attacker Value
Unknown
CVE-2016-9013
Disclosure Date: December 09, 2016 (last updated November 08, 2023)
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.
0
Attacker Value
Unknown
CVE-2016-6323
Disclosure Date: October 07, 2016 (last updated November 08, 2023)
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
0
Attacker Value
Unknown
CVE-2016-7167
Disclosure Date: October 07, 2016 (last updated November 08, 2023)
Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2016-7405
Disclosure Date: October 03, 2016 (last updated November 08, 2023)
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
0
Attacker Value
Unknown
CVE-2016-6494
Disclosure Date: October 03, 2016 (last updated November 08, 2023)
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
0
Attacker Value
Unknown
CVE-2016-7163
Disclosure Date: September 21, 2016 (last updated November 08, 2023)
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
0
Attacker Value
Unknown
CVE-2016-5157
Disclosure Date: September 11, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
0