Latest CVE Feed
-
7.0
HIGHCVE-2016-5652
An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a saved TIF... Read more
Affected Products : libtiff- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-5646
An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can cause a code execution. An attacker can send a malformed fil... Read more
Affected Products : perceptive_document_filters- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4336
An exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted Bzip2 document can lead to a stack-based buffer overflow causing an out-of-bounds write which under the right ci... Read more
Affected Products : perceptive_document_filters- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2016-4335
An exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a stack based buffer overflow resulting in remote code execution.... Read more
Affected Products : perceptive_document_filters- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4329
A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain unhandled window messages, an attacker can cause application termination and in the same way bypass KAV sel... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2016-4323
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide a... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4307
A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An att... Read more
Affected Products : internet_security- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4306
Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as pri... Read more
Affected Products : total_security- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4305
A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially crafted native api call can cause a access violation in KLIF kernel driver resulting in local denial of service. An att... Read more
Affected Products : internet_security- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4304
A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A specially crafted native api call request can cause a access violation exception in KLIF kernel driver resulting in local den... Read more
Affected Products : internet_security- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4298
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a list of elements using a length from the file. When calculating this length, an integer overflow can be mad... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4296
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at ... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4295
When opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation leading to a heap overlow can be made to occur in Hancom Office 2014. The vulnerability occurs when processing data for a f... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4294
When opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt to allocate space for an element using a length from the file. When copying user-supplied data to this buffer, howeve... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4292
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to allocate a heap buffer yet explicitly trust a size from the file when modifying data inside of it. Due to this, an agg... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4291
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the structure in an operation that can cause the integer to overflow. This result is then used to allocate memory to copy ... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4290
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a block of data within the file. When calculating this length, the application will use a value from the file... Read more
Affected Products : hancom_office_2014- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2016-4288
A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to execute arbitrary programs with SYSTEM privileges.... Read more
Affected Products : bluestacks- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-2380
An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get conver... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-2378
A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfiltered m... Read more
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025