Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2016-7448

больше 9 лет назад

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7447

больше 9 лет назад

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7446

больше 9 лет назад

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7445

почти 10 лет назад

convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7444

почти 10 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7440

почти 10 лет назад

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7439

почти 10 лет назад

The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7438

почти 10 лет назад

The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7434

больше 9 лет назад

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2016-7433

больше 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7431

больше 9 лет назад

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7429

больше 9 лет назад

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2016-7428

больше 9 лет назад

ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7427

больше 9 лет назад

The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7426

больше 9 лет назад

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2016-7425

почти 10 лет назад

The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7424

почти 10 лет назад

The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7423

почти 10 лет назад

The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects.

CVSS3: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2016-7422

почти 10 лет назад

The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.

CVSS3: 6
EPSS: Низкий
ubuntu логотип

CVE-2016-7421

почти 10 лет назад

The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-7448

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations) via vectors involving the header information and the file size.

CVSS3: 7.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7447

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7446

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. Note: This vulnerability exists due to an incomplete patch for CVE-2016-2317.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7445

convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.

CVSS3: 7.5
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7444

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 7.5
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7440

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7439

The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7438

The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7434

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

CVSS3: 7.5
53%
Средний
больше 9 лет назад
ubuntu логотип
CVE-2016-7433

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 5.3
10%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7431

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
9%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7429

NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.

CVSS3: 3.7
7%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7428

ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.

CVSS3: 4.3
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7427

The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.

CVSS3: 4.3
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7426

NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

CVSS3: 7.5
12%
Средний
больше 9 лет назад
ubuntu логотип
CVE-2016-7425

The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) via an ARCMSR_MESSAGE_WRITE_WQBUFFER control code.

CVSS3: 7.8
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7424

The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.

CVSS3: 5.5
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7423

The mptsas_process_scsi_io_request function in QEMU (aka Quick Emulator), when built with LSI SAS1068 Host Bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors involving MPTSASRequest objects.

CVSS3: 4.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7422

The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.

CVSS3: 6
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7421

The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the ring size.

CVSS3: 4.4
0%
Низкий
почти 10 лет назад

Уязвимостей на страницу