Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2016-7970

больше 9 лет назад

Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7969

больше 9 лет назад

The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7968

больше 9 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7967

больше 9 лет назад

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2016-7966

больше 9 лет назад

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7965

почти 10 лет назад

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7964

почти 10 лет назад

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-7958

больше 9 лет назад

In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7957

больше 9 лет назад

In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7954

больше 9 лет назад

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7953

почти 10 лет назад

Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7952

почти 10 лет назад

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7951

почти 10 лет назад

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7950

почти 10 лет назад

The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7949

почти 10 лет назад

Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7948

почти 10 лет назад

X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7947

почти 10 лет назад

Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7946

почти 10 лет назад

X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7945

почти 10 лет назад

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7944

почти 10 лет назад

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-7970

Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS3: 7.5
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7969

The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."

CVSS3: 7.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7968

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

CVSS3: 6.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7967

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

CVSS3: 8.1
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7966

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

CVSS3: 7.3
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

CVSS3: 6.5
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7964

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

CVSS3: 8.6
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7958

In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7957

In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7954

Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

CVSS3: 9.8
8%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7953

Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.

CVSS3: 9.8
3%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7952

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.

CVSS3: 7.5
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7951

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.

CVSS3: 9.8
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7950

The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.

CVSS3: 9.8
3%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7949

Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.

CVSS3: 9.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7948

X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.

CVSS3: 9.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7947

Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.

CVSS3: 9.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7946

X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.

CVSS3: 7.5
3%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7945

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.

CVSS3: 7.5
3%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7944

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.

CVSS3: 9.8
3%
Низкий
почти 10 лет назад

Уязвимостей на страницу