Total
1251 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7804 | 2 Apple, Php | 2 Mac Os X, Php | 2016-12-07 | 6.8 MEDIUM | N/A |
Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a denial of service (uninitialized pointer dereference and application crash) by including the / filename in a .zip PHAR archive. | |||||
CVE-2013-7437 | 1 Icoasoft | 1 Potrace | 2016-12-06 | 5.0 MEDIUM | N/A |
Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which triggers a buffer overflow. | |||||
CVE-2015-4067 | 1 Dell | 1 Netvault Backup | 2016-12-05 | 10.0 HIGH | N/A |
Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialized object, which triggers a heap-based buffer overflow. | |||||
CVE-2016-1968 | 1 Mozilla | 1 Firefox | 2016-12-02 | 6.8 MEDIUM | 8.8 HIGH |
Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression. | |||||
CVE-2016-0859 | 1 Advantech | 1 Webaccess | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request. | |||||
CVE-2015-2810 | 1 Hancom | 4 Hanword Viewer 2007, Hanword Viewer 2010, Hwp 2014 and 1 more | 2016-12-02 | 7.5 HIGH | N/A |
Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer 2007 and Viewer 2010 8.5.6.1158, and HwpViewer 2014 VP 9.1.0.2186, allows remote attackers to cause a denial of service (crash) and possibly "influence the program's execution flow" via a document with a large paragraph size, which triggers heap corruption. | |||||
CVE-2014-9766 | 2 Canonical, Pixman | 2 Ubuntu Linux, Pixman | 2016-12-02 | 7.5 HIGH | 9.8 CRITICAL |
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values. | |||||
CVE-2014-9604 | 2 Canonical, Ffmpeg | 2 Ubuntu Linux, Ffmpeg | 2016-12-02 | 7.5 HIGH | N/A |
libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Ut Video data, related to the (1) restore_median and (2) restore_median_il functions. | |||||
CVE-2014-8549 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 7.5 HIGH | N/A |
libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted On2 data. | |||||
CVE-2014-9602 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 7.5 HIGH | N/A |
libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relationship, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted X-Face image data. | |||||
CVE-2014-8546 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 7.5 HIGH | N/A |
Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted Cinepak video data. | |||||
CVE-2014-2972 | 1 Exim | 1 Exim | 2016-12-02 | 4.6 MEDIUM | N/A |
expand.c in Exim before 4.83 expands mathematical comparisons twice, which allows local users to gain privileges and execute arbitrary commands via a crafted lookup value. | |||||
CVE-2014-8545 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 7.5 HIGH | N/A |
libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows remote attackers to cause a denial of service (out-of-bounds access) or possibly have unspecified other impact via crafted PNG data. | |||||
CVE-2013-0862 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 9.3 HIGH | N/A |
Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access. | |||||
CVE-2013-0864 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 10.0 HIGH | N/A |
The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access. | |||||
CVE-2013-0876 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 9.3 HIGH | N/A |
Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access. | |||||
CVE-2013-7013 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 6.8 MEDIUM | N/A |
The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data. | |||||
CVE-2013-0875 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 9.3 HIGH | N/A |
The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a crafted PNG image, related to an out-of-bounds array access. | |||||
CVE-2013-7014 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 6.8 MEDIUM | N/A |
Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted PNG data. | |||||
CVE-2013-7010 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-02 | 6.8 MEDIUM | N/A |
Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data. |