Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-03-24 CVE-2017-5337 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
network
low complexity
opensuse gnu CWE-119
critical
9.8
2017-03-24 CVE-2017-5336 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
network
low complexity
opensuse gnu CWE-119
critical
9.8
2017-03-24 CVE-2016-10133 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Artifex Mujs
Heap-based buffer overflow in the js_stackoverflow function in jsrun.c in Artifex Software, Inc.
network
low complexity
artifex CWE-119
critical
9.8
2017-03-24 CVE-2016-10128 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libgit2 Project Libgit2 0.25.0
Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.
network
low complexity
libgit2-project CWE-119
critical
9.8
2017-03-23 CVE-2017-7246 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pcre 8.40
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 268) or possibly have unspecified other impact via a crafted file.
local
low complexity
pcre CWE-119
7.8
2017-03-23 CVE-2017-7245 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Pcre 8.40
Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.
local
low complexity
pcre CWE-119
7.8
2017-03-23 CVE-2016-9556 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
5.5
2017-03-23 CVE-2016-9264 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libming 0.4.7
Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
local
low complexity
libming CWE-119
5.5
2017-03-23 CVE-2016-9011 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Wvware Libwmf 0.2.8.4
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.
local
low complexity
wvware CWE-119
5.5
2017-03-23 CVE-2016-8886 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Jasper Project Jasper
The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.
local
low complexity
jasper-project CWE-119
7.8