Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-03 CVE-2016-3127 Information Exposure vulnerability in Blackberry Good Control Server 2.2.511.26
An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote attackers to gain and use logged encryption keys to access certain resources within a customer's Good deployment by gaining access to certain diagnostic log files through either a valid logon or an unrelated compromise of the server.
network
low complexity
blackberry CWE-200
7.5
2017-03-03 CVE-2016-10070 Out-of-bounds Read vulnerability in multiple products
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
local
low complexity
imagemagick opensuse CWE-125
5.5
2017-03-03 CVE-2016-10066 Classic Buffer Overflow vulnerability in Imagemagick
Buffer overflow in the ReadVIFFImage function in coders/viff.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a crafted file.
local
low complexity
imagemagick CWE-120
5.5
2017-03-03 CVE-2016-10065 Improper Access Control vulnerability in multiple products
The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.
local
low complexity
imagemagick opensuse CWE-284
7.8
2017-03-03 CVE-2016-10061 Unchecked Return Value vulnerability in Imagemagick
The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.
network
low complexity
imagemagick CWE-252
6.5
2017-03-03 CVE-2016-7972 Resource Management Errors vulnerability in multiple products
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
network
low complexity
opensuse fedoraproject libass-project CWE-399
7.5
2017-03-03 CVE-2016-7970 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
fedoraproject libass-project CWE-119
7.5
2017-03-03 CVE-2016-7969 Out-of-bounds Read vulnerability in multiple products
The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization."
network
low complexity
opensuse fedoraproject libass-project CWE-125
7.5
2017-03-03 CVE-2016-7409 Information Exposure vulnerability in Dropbear SSH Project Dropbear SSH
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
local
low complexity
dropbear-ssh-project CWE-200
5.5
2017-03-03 CVE-2016-7408 Improper Access Control vulnerability in Dropbear SSH Project Dropbear SSH
The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.
network
low complexity
dropbear-ssh-project CWE-284
8.8