Latest CVE Feed
-
10.0
HIGHCVE-2016-0842
The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media f... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0841
media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a ... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0840
Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0839
post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal ... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0838
Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service (me... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0837
MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memor... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0836
Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0835
decoder/impeg2d_dec_hdr.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a certain negative value, aka internal bug ... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0834
An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.... Read more
Affected Products : android- Published: Apr. 18, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-1340
Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837.... Read more
Affected Products : unified_computing_system_platform_emulator- Published: Apr. 16, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1339
Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.... Read more
Affected Products : unified_computing_system_platform_emulator- Published: Apr. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-5271
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might all... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3144
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7676
Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.... Read more
Affected Products : moveit_dmz- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2015-5348
Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in ... Read more
Affected Products : camel- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-3961
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2212
The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Community Edition before 1.9.2.3 allows remote attackers to obtain sensitive order ... Read more
Affected Products : magento- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2146
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POS... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2145
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-2076
Client Integration Plugin (CIP) in VMware vCenter Server 5.5 U3a, U3b, and U3c and 6.0 before U2; vCloud Director 5.5.5; and vRealize Automation Identity Appliance 6.2.4 before 6.2.4.1 mishandles session content, which allows remote attackers to hijack se... Read more
- Published: Apr. 15, 2016
- Modified: Apr. 12, 2025