|
258061
|
6.5 |
MEDIUM
Network
|
redhat xmlsoft
|
jboss_core_services libxml2
|
libxml2, as used in Red Hat JBoss Core Services and when in recovery mode, allows context-dependent attackers to cause a denial of service (stack consumption) via a crafted XML document. NOTE: this …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9596
|
2024-11-21 12:01 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258062
|
7.8 |
HIGH
Local
|
redhat jasper_project oracle
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_linux_server_eus jasper outside_i…
|
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-9583
|
2024-11-21 12:01 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258063
|
8.8 |
HIGH
Network
|
uclouvain
|
openjpeg
|
An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.
|
-
|
CVE-2016-9580
|
2024-11-21 12:01 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258064
|
7.5 |
HIGH
Network
|
redhat
|
enterprise_linux_desktop enterprise_linux_workstation ceph_storage_osd ceph_storage_mon enterprise_linux_server ceph_storage
|
A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw …
|
-
|
CVE-2016-9579
|
2024-11-21 12:01 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258065
|
6.5 |
MEDIUM
Network
|
uclouvain debian
|
openjpeg debian_linux
|
A NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code responsible for decoding the input image, an application using openj…
|
-
|
CVE-2016-9572
|
2024-11-21 12:01 |
2018-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258066
|
8.8 |
HIGH
Network
|
uclouvain
|
openjpeg
|
An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.
|
-
|
CVE-2016-9581
|
2024-11-21 12:01 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258067
|
8.1 |
HIGH
Network
|
uclouvain redhat debian
|
openjpeg enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus debian_linux
|
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, pote…
|
-
|
CVE-2016-9573
|
2024-11-21 12:01 |
2018-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258068
|
7.5 |
HIGH
Network
|
canonical xmlsoft debian hp opensuse
|
ubuntu_linux libxml2 debian_linux icewall_file_manager icewall_federation_agent leap
|
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service att…
|
-
|
CVE-2016-9597
|
2024-11-21 12:01 |
2018-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258069
|
9.9 |
CRITICAL
Network
|
qemu redhat citrix debian
|
qemu enterprise_linux_desktop xenserver enterprise_linux_workstation openstack enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus
|
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9603
|
2024-11-21 12:01 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258070
|
7.5 |
HIGH
Network
|
spice_project redhat debian
|
spice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus
|
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to …
|
CWE-20
Improper Input Validation
|
CVE-2016-9578
|
2024-11-21 12:01 |
2018-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|