CVE-2016-9453
- EPSS 0.42%
- Published 27.01.2017 17:59:00
- Last modified 20.04.2025 01:37:25
The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.
CVE-2016-5316
- EPSS 0.86%
- Published 20.01.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.
CVE-2016-5317
- EPSS 0.61%
- Published 20.01.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.
CVE-2016-5321
- EPSS 0.17%
- Published 20.01.2017 15:59:00
- Last modified 20.04.2025 01:37:25
The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image.
CVE-2016-5323
- EPSS 1.11%
- Published 20.01.2017 15:59:00
- Last modified 20.04.2025 01:37:25
The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.
CVE-2016-7787
- EPSS 0.54%
- Published 23.12.2016 22:59:00
- Last modified 12.04.2025 10:46:40
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
CVE-2016-9427
- EPSS 2.41%
- Published 12.12.2016 02:59:16
- Last modified 12.04.2025 10:46:40
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
CVE-2016-6323
- EPSS 1.13%
- Published 07.10.2016 14:59:06
- Last modified 12.04.2025 10:46:40
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang)...
CVE-2016-6905
- EPSS 1.09%
- Published 03.10.2016 21:59:05
- Last modified 12.04.2025 10:46:40
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA image.
CVE-2013-4118
- EPSS 1.9%
- Published 03.10.2016 21:59:00
- Last modified 12.04.2025 10:46:40
FreeRDP before 1.1.0-beta1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors.