Latest CVE Feed
-
9.8
CRITICALCVE-2016-7942
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6313
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 4640 bi... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5407
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4322
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.... Read more
Affected Products : bladelogic_server_automation_console- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6722
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outsid... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6720
An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to access data outsid... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-6712
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. Thi... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-6711
A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-01 could enable an attacker to use a specially crafted file to cause a device hang or reboot. Thi... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-6706
An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because ... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-6699
A remote code execution vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critic... Read more
Affected Products : android- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-5647
The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.... Read more
Affected Products : graphics_driver- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7440
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7439
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.... Read more
Affected Products : wolfssl- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-7438
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.... Read more
Affected Products : wolfssl- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2015-5073
Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of service (crash) or obtain sensitive information from heap memory and possibly bypass the ASLR protection mechani... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-3418
The ProcPutImage function in dix/dispatch.c in X.Org Server (aka xserver and xorg-server) before 1.16.4 allows attackers to cause a denial of service (divide-by-zero and crash) via a zero-height PutImage request.... Read more
- Published: Dec. 13, 2016
- Modified: Aug. 29, 2025
-
7.5
HIGHCVE-2015-3217
PCRE 7.8 and 8.32 through 8.37, and PCRE2 10.10 mishandle group empty matches, which might allow remote attackers to cause a denial of service (stack-based buffer overflow) via a crafted regular expression, as demonstrated by /^(?:(?(1)\\.|([^\\\\W_])?)+)... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-3210
Heap-based buffer overflow in PCRE 8.34 through 8.37 and PCRE2 10.10 allows remote attackers to execute arbitrary code via a crafted regular expression, as demonstrated by /^(?P=B)((?P=B)(?J:(?P<B>c)(?P<B>a(?P=B)))>WGXCREDITS)/, a different vulnerability ... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-6520
Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.... Read more
Affected Products : imagemagick- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6491
Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.... Read more
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025