Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-01-31 CVE-2016-9260 Cross-site Scripting vulnerability in Tenable Nessus
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
network
low complexity
tenable CWE-79
5.4
2017-01-31 CVE-2016-8703 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8702.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8702 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, and CVE-2016-8703.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8701 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8702, and CVE-2016-8703.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8700 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8699 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8700, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8698 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Potrace Project Potrace
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.
local
low complexity
potrace-project CWE-119
7.8
2017-01-31 CVE-2016-8697 Divide By Zero vulnerability in Potrace Project Potrace
The bm_new function in bitmap.h in potrace before 1.13 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted BMP image.
local
low complexity
potrace-project CWE-369
5.5
2017-01-31 CVE-2016-8696 NULL Pointer Dereference vulnerability in Potrace Project Potrace
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8695.
local
low complexity
potrace-project CWE-476
5.5
2017-01-31 CVE-2016-8695 NULL Pointer Dereference vulnerability in Potrace Project Potrace
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8696.
local
low complexity
potrace-project CWE-476
5.5