Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,084 CVEs tagged with CWE-125670 Critical, 3,766 High, 4,140 Medium, 503 Low, 5 Unrated.

CVE-2015-8915

Published Sep 20, 2016

bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7175

Published Sep 9, 2016

epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to cause a denial of service (ou…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6263

Published Sep 7, 2016

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2064

Published Aug 7, 2016

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5352

Published Aug 7, 2016

epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (appl…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5114

Published Aug 7, 2016

sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain s…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5093

Published Aug 7, 2016

The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' char…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7456

Published Aug 7, 2016

gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3855

Published Aug 6, 2016

drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows attackers to cause a denial of s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3854

Published Aug 6, 2016

drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attackers to cause a denial of servic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1513

Published Aug 5, 2016

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted Me…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2180

Published Aug 1, 2016

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6294

Published Jul 25, 2016

The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly restrict calls to the IC…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4652

Published Jul 22, 2016

CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a denial of service (out…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4628

Published Jul 22, 2016

IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-b…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 8,976-9,000 of 9,084 CVEsPage 360 of 364