Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,306 CVEs tagged with CWE-125694 Critical, 3,864 High, 4,234 Medium, 511 Low, 3 Unrated.

CVE-2017-7206

Published Mar 21, 2017

The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or obtain sensitive information f…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6829

Published Mar 20, 2017

The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5956

Published Mar 20, 2017

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8984

Published Mar 20, 2017

The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6969

Published Mar 17, 2017

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to a…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-5667

Published Mar 16, 2017

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8897

Published Mar 15, 2017

The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6430

Published Mar 15, 2017

The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6851

Published Mar 15, 2017

The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6840

Published Mar 15, 2017

The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6437

Published Mar 15, 2017

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6906

Published Mar 15, 2017

The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6335

Published Mar 14, 2017

The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application cra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10172

Published Mar 14, 2017

The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10171

Published Mar 14, 2017

The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10170

Published Mar 14, 2017

The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10169

Published Mar 14, 2017

The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6800

Published Mar 10, 2017

An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, related to MAPIPrint() in libyt…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 9,001-9,025 of 9,306 CVEsPage 361 of 373