Vulnerabilities > Data Processing Errors

DATE CVE VULNERABILITY TITLE RISK
2017-01-10 CVE-2016-6287 Data Processing Errors vulnerability in Call-Cc Http-Client 0.4.2/0.9
The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process.
network
low complexity
call-cc CWE-19
7.5
2017-01-10 CVE-2016-6286 Data Processing Errors vulnerability in Call-Cc Http-Client 0.4.2
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a "httpoxy" attack).
network
low complexity
call-cc CWE-19
7.5
2017-01-06 CVE-2016-1549 Data Processing Errors vulnerability in NTP 4.2.8
A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.
network
low complexity
ntp CWE-19
6.5
2017-01-06 CVE-2016-1548 Data Processing Errors vulnerability in NTP 4.2.8
An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server.
network
low complexity
ntp CWE-19
7.2
2016-12-29 CVE-2016-10081 Data Processing Errors vulnerability in Shutter-Project Shutter 0.93/0.93.1
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.
local
low complexity
shutter-project CWE-19
7.8
2016-12-29 CVE-2015-0854 Data Processing Errors vulnerability in Shutter-Project Shutter 0.93/0.93.1
App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.
local
low complexity
shutter-project CWE-19
7.8
2016-12-20 CVE-2016-7292 Data Processing Errors vulnerability in Microsoft products
The Installer in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Installer Elevation of Privilege Vulnerability."
local
low complexity
microsoft CWE-19
7.8
2016-12-20 CVE-2016-7275 Data Processing Errors vulnerability in Microsoft Office 2010/2013/2016
Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."
local
low complexity
microsoft CWE-19
7.8
2016-12-20 CVE-2016-7274 Data Processing Errors vulnerability in Microsoft products
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-19
8.8
2016-12-20 CVE-2016-7273 Data Processing Errors vulnerability in Microsoft Windows 10 and Windows Server 2016
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."
network
low complexity
microsoft CWE-19
8.8