|
266901
|
7.0 |
HIGH
Local
|
libtiff
|
libtiff
|
An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code e…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5652
|
2024-11-21 11:54 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266902
|
7.8 |
HIGH
Local
|
lexmark
|
perceptive_document_filters
|
An exploitable heap overflow vulnerability exists in the Compound Binary File Format (CBFF) parser functionality of Lexmark Perceptive Document Filters library. A specially crafted CBFF file can caus…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5646
|
2024-11-21 11:54 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266903
|
5.3 |
MEDIUM
Network
|
vmware
|
identity_manager vrealize_automation
|
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2016-5334
|
2024-11-21 11:54 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266904
|
5.5 |
MEDIUM
Local
|
vmware
|
fusion
|
VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecif…
|
CWE-200
Information Exposure
|
CVE-2016-5329
|
2024-11-21 11:54 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266905
|
5.5 |
MEDIUM
Local
|
vmware
|
tools
|
VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism v…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-5328
|
2024-11-21 11:54 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266906
|
6.1 |
MEDIUM
Network
|
horde
|
groupware
|
Cross-site scripting (XSS) vulnerability in the Horde Text Filter API in Horde Groupware and Horde Groupware Webmail Edition before 5.2.16 allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5303
|
2024-11-21 11:54 |
2016-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266907
|
6.1 |
MEDIUM
Network
|
open-xchange
|
open-xchange_appsuite
|
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within scheduling E-Mails. This content, for example an appointment's l…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5740
|
2024-11-21 11:54 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266908
|
9.8 |
CRITICAL
Network
|
x.org fedoraproject
|
libxv fedora
|
The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifica…
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2016-5407
|
2024-11-21 11:54 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266909
|
7.8 |
HIGH
Local
|
intel
|
graphics_driver
|
The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash)…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-5647
|
2024-11-21 11:54 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266910
|
9.8 |
CRITICAL
Network
|
oracle imagemagick
|
solaris imagemagick
|
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixe…
|
CWE-20
Improper Input Validation
|
CVE-2016-5691
|
2024-11-21 11:54 |
2016-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|