Latest CVE Feed
-
7.5
HIGHCVE-2017-5840
The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5839
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors i... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5838
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-5837
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9244
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) ses... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager big-ip_protocol_security_module- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-8494
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.... Read more
Affected Products : connect- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6173
NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer with unlimited data.... Read more
Affected Products : nsd- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-6171
Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXFR.... Read more
Affected Products : knot_dns- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5727
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.... Read more
Affected Products : simple_machines_forum- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5726
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.... Read more
Affected Products : simple_machines_forum- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4988
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.... Read more
Affected Products : build_failure_analyzer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4987
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.... Read more
Affected Products : image_gallery- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4986
Directory traversal vulnerability in the TAP plugin before 1.25 in Jenkins allows remote attackers to read arbitrary files via an unspecified parameter.... Read more
Affected Products : tap- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3102
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.... Read more
Affected Products : script_security- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3101
Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.... Read more
Affected Products : extra_columns- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2148
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.... Read more
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-2147
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.... Read more
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10199
The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10198
The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.... Read more
Affected Products : gstreamer- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10192
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.... Read more
Affected Products : ffmpeg- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025