Latest CVE Feed
-
8.8
HIGHCVE-2010-5327
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.... Read more
Affected Products : liferay_portal- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0398
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Produc... Read more
Affected Products : android- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9813
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9812
The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a too small section.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-9811
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9810
The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via an invalid file, which triggers an incorrect unref ca... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9809
Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted file, which triggers an out-of-bounds read.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9808
The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9807
The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.... Read more
Affected Products : gstreamer- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9312
ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-9311
ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.... Read more
Affected Products : ntp- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-9310
The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.... Read more
Affected Products : ntp- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9107
The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : gajim-otr- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8883
The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.... Read more
Affected Products : jasper- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8882
The jpc_dec_tilefini function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.... Read more
Affected Products : jasper- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-8671
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix f... Read more
Affected Products : matrixssl- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8467
An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely p... Read more
Affected Products : android- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7434
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-7433
NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-7431
NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.... Read more
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025