Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-02-09 CVE-2017-5844 Divide By Zero vulnerability in Gstreamer Project Gstreamer
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted ASF file.
local
low complexity
gstreamer-project CWE-369
5.5
2017-02-09 CVE-2017-5843 Use After Free vulnerability in Gstreamer Project Gstreamer
Multiple use-after-free vulnerabilities in the (1) gst_mini_object_unref, (2) gst_tag_list_unref, and (3) gst_mxf_demux_update_essence_tracks functions in GStreamer before 1.10.3 allow remote attackers to cause a denial of service (crash) via vectors involving stream tags, as demonstrated by 02785736.mxf.
network
low complexity
gstreamer-project CWE-416
7.5
2017-02-09 CVE-2017-5842 Out-of-bounds Write vulnerability in Gstreamer Project Gstreamer
The html_context_handle_element function in gst/subparse/samiparse.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted SMI file, as demonstrated by OneNote_Manager.smi.
local
low complexity
gstreamer-project CWE-787
5.5
2017-02-09 CVE-2017-5841 Out-of-bounds Read vulnerability in Gstreamer Project Gstreamer
The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags.
network
low complexity
gstreamer-project CWE-125
7.5
2017-02-09 CVE-2017-5840 Out-of-bounds Read vulnerability in Gstreamer Project Gstreamer
The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.
network
low complexity
gstreamer-project CWE-125
7.5
2017-02-09 CVE-2017-5839 Uncontrolled Recursion vulnerability in Gstreamer Project Gstreamer
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.
network
low complexity
gstreamer-project CWE-674
7.5
2017-02-09 CVE-2017-5838 Out-of-bounds Read vulnerability in Gstreamer Project Gstreamer
The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string.
network
low complexity
gstreamer-project CWE-125
7.5
2017-02-09 CVE-2017-5837 Divide By Zero vulnerability in Gstreamer Project Gstreamer
The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (floating point exception and crash) via a crafted video file.
local
low complexity
gstreamer-project CWE-369
5.5
2017-02-09 CVE-2016-9244 Information Exposure vulnerability in F5 products
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory.
network
low complexity
f5 CWE-200
7.5
2017-02-09 CVE-2016-8494 Permissions, Privileges, and Access Controls vulnerability in Fortinet Connect
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.
network
low complexity
fortinet CWE-264
7.2