|
257171
|
7.8 |
HIGH
Local
|
libtiff opensuse debian
|
libtiff opensuse debian_linux
|
The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIF…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-9453
|
2024-11-21 12:01 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257172
|
7.5 |
HIGH
Network
|
libtiff opensuse
|
libtiff opensuse
|
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9448
|
2024-11-21 12:01 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257173
|
7.8 |
HIGH
Local
|
gstreamer_project
|
gstreamer
|
The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music f…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2016-9447
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257174
|
7.5 |
HIGH
Network
|
gstreamer_project redhat fedoraproject
|
gstreamer enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_eus enterprise_linux_server_tus fedora
|
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that…
|
CWE-665
Improper Initialization
|
CVE-2016-9446
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257175
|
7.5 |
HIGH
Network
|
gstreamer_project
|
gstreamer
|
Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9445
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257176
|
5.5 |
MEDIUM
Local
|
gnu debian redhat
|
bash debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_server_tus
|
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
|
CWE-416
Use After Free
|
CVE-2016-9401
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257177
|
7.8 |
HIGH
Local
|
citrix xen
|
xenserver xen
|
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9386
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257178
|
6.0 |
MEDIUM
Local
|
xen citrix
|
xen xenserver
|
The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical add…
|
CWE-20
Improper Input Validation
|
CVE-2016-9385
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257179
|
8.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute …
|
CWE-20
Improper Input Validation
|
CVE-2016-9383
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257180
|
7.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a gue…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9382
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|