Vulnerabilities > Improper Restriction of Operations within the Bounds of a Memory Buffer

DATE CVE VULNERABILITY TITLE RISK
2017-03-15 CVE-2017-5580 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Virglrenderer Project Virglrenderer 0.2.0/0.4.0/0.5.0
The parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and process crash) via a crafted texture instruction.
local
low complexity
virglrenderer-project CWE-119
7.1
2017-03-15 CVE-2017-5358 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Easycom-Aura Easycom for PHP 4.0.0.29
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbitrary code via the server argument to the (1) i5_connect, (2) i5_pconnect, or (3) i5_private_connect API function.
network
low complexity
easycom-aura CWE-119
critical
9.8
2017-03-15 CVE-2017-6852 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Jasper Project Jasper
Heap-based buffer overflow in the jpc_dec_decodepkt function in jpc_t2dec.c in JasPer 2.0.10 allows remote attackers to have unspecified impact via a crafted image.
local
low complexity
jasper-project CWE-119
7.8
2017-03-15 CVE-2017-6844 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Podofo Project Podofo 0.9.4
Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.
local
low complexity
podofo-project CWE-119
7.8
2017-03-15 CVE-2017-6843 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Podofo Project Podofo 0.9.4
Heap-based buffer overflow in the PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.
local
low complexity
podofo-project CWE-119
7.8
2017-03-15 CVE-2017-6828 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Audiofile 0.3.6
Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file.
local
low complexity
audiofile CWE-119
7.8
2017-03-15 CVE-2017-6827 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Audiofile 0.3.6
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file.
local
low complexity
audiofile CWE-119
7.8
2017-03-15 CVE-2017-6435 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libplist Project Libplist 1.12
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.
local
low complexity
libplist-project CWE-119
5.0
2017-03-15 CVE-2017-6209 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Virglrenderer Project Virglrenderer 0.2.0/0.4.0/0.5.0
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties.
local
low complexity
virglrenderer-project CWE-119
6.5
2017-03-15 CVE-2017-5994 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Virglrenderer Project Virglrenderer 0.2.0/0.4.0/0.5.0
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.
local
low complexity
virglrenderer-project CWE-119
5.5