CVE-2016-8569
- EPSS 0.74%
- Published 03.02.2017 15:59:00
- Last modified 20.04.2025 01:37:25
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
CVE-2016-9085
- EPSS 0.11%
- Published 03.02.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
CVE-2016-9108
- EPSS 0.83%
- Published 03.02.2017 15:59:00
- Last modified 20.04.2025 01:37:25
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
CVE-2015-7977
- EPSS 9.71%
- Published 30.01.2017 21:59:00
- Last modified 20.04.2025 01:37:25
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2016-9446
- EPSS 1.28%
- Published 23.01.2017 21:59:03
- Last modified 20.04.2025 01:37:25
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
CVE-2015-8854
- EPSS 1.02%
- Published 23.01.2017 21:59:00
- Last modified 20.04.2025 01:37:25
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (...
CVE-2016-7543
- EPSS 0.12%
- Published 19.01.2017 20:59:00
- Last modified 20.04.2025 01:37:25
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
CVE-2016-7545
- EPSS 0.04%
- Published 19.01.2017 20:59:00
- Last modified 20.04.2025 01:37:25
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
CVE-2016-9811
- EPSS 0.49%
- Published 13.01.2017 16:59:01
- Last modified 20.04.2025 01:37:25
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVE-2016-2090
- EPSS 1.71%
- Published 13.01.2017 16:59:00
- Last modified 20.04.2025 01:37:25
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.