Latest CVE Feed
-
5.5
MEDIUMCVE-2016-7905
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7785
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7562
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7555
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-7502
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-7450
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7122
The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6881
The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6671
The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.... Read more
Affected Products : ffmpeg- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-6659
Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA log... Read more
- Published: Dec. 23, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7954
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.... Read more
Affected Products : bundler- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-9675
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.... Read more
- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-9181
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disc... Read more
Affected Products : image-info_for_perl- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-9180
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.... Read more
Affected Products : xml-twig_for_perl- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-9179
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.... Read more
Affected Products : lynx- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2016-7091
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted progr... Read more
- Published: Dec. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-7172
NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.... Read more
Affected Products : snap_creator_framework- Published: Dec. 21, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5851
python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.... Read more
Affected Products : python-docx- Published: Dec. 21, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2349
Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.... Read more
Affected Products : remedy_action_request_system- Published: Dec. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-9757
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field. Once this tag is viewed in the Tag Detail page ... Read more
Affected Products : nexpose- Published: Dec. 20, 2016
- Modified: Apr. 12, 2025