Show filters
700 Total Results
Displaying 91-100 of 700
Sort by:
Attacker Value
Unknown
CVE-2016-4303
Disclosure Date: September 26, 2016 (last updated January 16, 2025)
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2016-6265
Disclosure Date: September 22, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2015-8948
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2016-6262
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
0
Attacker Value
Unknown
CVE-2016-6855
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
0
Attacker Value
Unknown
CVE-2016-5421
Disclosure Date: August 10, 2016 (last updated November 08, 2023)
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-5772
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.
0
Attacker Value
Unknown
CVE-2016-5770
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.
0
Attacker Value
Unknown
CVE-2016-5771
Disclosure Date: August 07, 2016 (last updated November 25, 2024)
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.
0
Attacker Value
Unknown
CVE-2016-3992
Disclosure Date: July 26, 2016 (last updated November 25, 2024)
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
0