Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,084 CVEs tagged with CWE-125670 Critical, 3,766 High, 4,140 Medium, 503 Low, 5 Unrated.

CVE-2016-7914

Published Nov 16, 2016

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtai…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7506

Published Oct 29, 2016

An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9017

Published Oct 28, 2016

Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted Java…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3658

Published Oct 3, 2016

The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3634

Published Oct 3, 2016

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3633

Published Oct 3, 2016

The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src var…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3631

Published Oct 3, 2016

The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3625

Published Oct 3, 2016

tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3621

Published Oct 3, 2016

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buff…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3620

Published Oct 3, 2016

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buff…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3619

Published Oct 3, 2016

The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of se…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6306

Published Sep 26, 2016

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate oper…

CVSS 5.9 · Medium

CVE-2016-5271

Published Sep 22, 2016

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2827

Published Sep 22, 2016

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8927

Published Sep 20, 2016

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,951-8,975 of 9,084 CVEsPage 359 of 364