Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2016-7986

больше 9 лет назад

The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7985

больше 9 лет назад

The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7984

больше 9 лет назад

The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7983

больше 9 лет назад

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7979

почти 10 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2016-7978

почти 10 лет назад

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVSS3: 5.8
EPSS: Низкий
redhat логотип

CVE-2016-7977

почти 10 лет назад

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2016-7976

почти 10 лет назад

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

CVSS3: 7.1
EPSS: Средний
redhat логотип

CVE-2016-7975

больше 9 лет назад

The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7974

больше 9 лет назад

The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7973

больше 9 лет назад

The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-7968

почти 10 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-7967

почти 10 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2016-7966

почти 10 лет назад

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-7958

почти 10 лет назад

In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2016-7957

почти 10 лет назад

In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2016-7954

почти 10 лет назад

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2016-7953

почти 10 лет назад

Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2016-7952

почти 10 лет назад

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.

CVSS3: 5
EPSS: Низкий
redhat логотип

CVE-2016-7951

почти 10 лет назад

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-7986

The GeoNetworking parser in tcpdump before 4.9.0 has a buffer overflow in print-geonet.c, multiple functions.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7985

The CALM FAST parser in tcpdump before 4.9.0 has a buffer overflow in print-calm-fast.c:calm_fast_print().

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7984

The TFTP parser in tcpdump before 4.9.0 has a buffer overflow in print-tftp.c:tftp_print().

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7983

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

CVSS3: 6.5
4%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7979

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

CVSS3: 5.8
6%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7978

Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

CVSS3: 5.8
6%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7977

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use of the .libfile operator in a crafted postscript document.

CVSS3: 6.2
5%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7976

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

CVSS3: 7.1
23%
Средний
почти 10 лет назад
redhat логотип
CVE-2016-7975

The TCP parser in tcpdump before 4.9.0 has a buffer overflow in print-tcp.c:tcp_print().

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7974

The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7973

The AppleTalk parser in tcpdump before 4.9.0 has a buffer overflow in print-atalk.c, multiple functions.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7968

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 4.3
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

CVSS3: 6.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7966

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

CVSS3: 4.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7958

In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.

CVSS3: 5.9
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7957

In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.

CVSS3: 5.9
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7954

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

CVSS3: 4.9
8%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7953

Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.

CVSS3: 5
3%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7952

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.

CVSS3: 5
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7951

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.

CVSS3: 5
2%
Низкий
почти 10 лет назад

Уязвимостей на страницу