|
265381
|
5.5 |
MEDIUM
Local
|
ffmpeg
|
ffmpeg
|
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7562
|
2024-11-21 11:58 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265382
|
5.5 |
MEDIUM
Local
|
ffmpeg
|
ffmpeg
|
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
|
CWE-200
Information Exposure
|
CVE-2016-7555
|
2024-11-21 11:58 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265383
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7502
|
2024-11-21 11:58 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265384
|
7.8 |
HIGH
Local
|
ffmpeg
|
ffmpeg
|
The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7450
|
2024-11-21 11:58 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265385
|
9.8 |
CRITICAL
Network
|
bundler
|
bundler
|
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
|
CWE-94
Code Injection
|
CVE-2016-7954
|
2024-11-21 11:58 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265386
|
8.0 |
HIGH
Adjacent
|
technicolor
|
xfinity_gateway_router_dpc3941t_firmware
|
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remo…
|
CWE-352
Origin Validation Error
|
CVE-2016-7454
|
2024-11-21 11:58 |
2016-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265387
|
6.1 |
MEDIUM
Network
|
adobe
|
robohelp
|
Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7891
|
2024-11-21 11:58 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265388
|
8.8 |
HIGH
Network
|
adobe
|
flash_player_desktop_runtime flash_player
|
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have security bypass vulnerability in the implementation of the same origin policy.
|
NVD-CWE-noinfo
|
CVE-2016-7890
|
2024-11-21 11:58 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265389
|
7.5 |
HIGH
Network
|
adobe
|
digital_editions
|
Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to information disclosure.
|
CWE-200
Information Exposure
|
CVE-2016-7889
|
2024-11-21 11:58 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265390
|
5.3 |
MEDIUM
Network
|
adobe
|
digital_editions
|
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.
|
CWE-200
Information Exposure
|
CVE-2016-7888
|
2024-11-21 11:58 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|