Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2016-9312

больше 9 лет назад

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2016-9311

больше 9 лет назад

ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2016-9310

больше 9 лет назад

The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

CVSS3: 4.8
EPSS: Средний
redhat логотип

CVE-2016-9299

почти 10 лет назад

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

CVSS3: 8.1
EPSS: Критический
redhat логотип

CVE-2016-9298

почти 10 лет назад

Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-9297

почти 10 лет назад

The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-9279

почти 10 лет назад

Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2016-9278

почти 10 лет назад

The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-9276

почти 10 лет назад

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-9275

почти 10 лет назад

Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-9273

почти 10 лет назад

tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-9262

почти 10 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2016-9243

почти 10 лет назад

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2016-9191

почти 10 лет назад

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2016-9190

почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2016-9189

почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-9185

почти 10 лет назад

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 3.5
EPSS: Низкий
redhat логотип

CVE-2016-9181

почти 10 лет назад

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2016-9180

почти 10 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2016-9179

почти 10 лет назад

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-9312

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

CVSS3: 7.5
31%
Средний
больше 9 лет назад
redhat логотип
CVE-2016-9311

ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.

CVSS3: 5.9
11%
Средний
больше 9 лет назад
redhat логотип
CVE-2016-9310

The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

CVSS3: 4.8
11%
Средний
больше 9 лет назад
redhat логотип
CVE-2016-9299

The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

CVSS3: 8.1
97%
Критический
почти 10 лет назад
redhat логотип
CVE-2016-9298

Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.

CVSS3: 3.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9297

The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.

CVSS3: 3.3
6%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9279

Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.

CVSS3: 7
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9278

The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.

CVSS3: 6.5
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9276

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 3.3
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9275

Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 3.3
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9273

tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.

CVSS3: 3.3
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9262

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 7
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9243

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

CVSS3: 4.8
3%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9190

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9189

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 6.5
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9185

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 3.5
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9181

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

CVSS3: 7.1
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9180

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 7.1
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-9179

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

CVSS3: 5.4
2%
Низкий
почти 10 лет назад

Уязвимостей на страницу