|
265401
|
5.5 |
MEDIUM
Local
|
graphicsmagick debian suse opensuse
|
graphicsmagick debian_linux studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo leap opensuse
|
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartEle…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2318
|
2024-11-21 11:48 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265402
|
5.5 |
MEDIUM
Local
|
graphicsmagick debian suse opensuse
|
graphicsmagick debian_linux studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo leap opensuse
|
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) G…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2317
|
2024-11-21 11:48 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265403
|
5.9 |
MEDIUM
Network
|
squareup
|
okhttp3 okhttp
|
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-2402
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265404
|
7.8 |
HIGH
Local
|
libquicktime
|
libquicktime
|
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted h…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2399
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265405
|
5.3 |
MEDIUM
Network
|
dest-unreach
|
socat
|
The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.
|
CWE-320
Key Management Errors
|
CVE-2016-2217
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265406
|
5.9 |
MEDIUM
Network
|
ntp
|
ntp
|
ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2519
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265407
|
5.3 |
MEDIUM
Network
|
ntp
|
ntp
|
NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending…
|
CWE-20
Improper Input Validation
|
CVE-2016-2517
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265408
|
5.3 |
MEDIUM
Network
|
ntp
|
ntp
|
NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directi…
|
CWE-20
Improper Input Validation
|
CVE-2016-2516
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265409
|
5.3 |
MEDIUM
Network
|
ntp debian netapp oracle redhat freebsd siemens
|
ntp debian_linux oncommand_balance clustered_data_ontap data_ontap oncommand_performance_manager oncommand_unified_manager_for_clustered_data_ontap communications_user_data_repos…
|
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-2518
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265410
|
9.8 |
CRITICAL
Network
|
avaya
|
vsp_operating_system_software
|
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attack…
|
CWE-19
Data Processing Errors
|
CVE-2016-2783
|
2024-11-21 11:48 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|