Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-17 CVE-2016-5043 Out-of-bounds Read vulnerability in Libdwarf Project Libdwarf
The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.
network
low complexity
libdwarf-project CWE-125
7.5
2017-02-17 CVE-2016-5042 Infinite Loop vulnerability in Libdwarf Project Libdwarf
The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.
network
low complexity
libdwarf-project CWE-835
7.5
2017-02-17 CVE-2016-5040 Out-of-bounds Read vulnerability in Libdwarf Project Libdwarf
libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.
network
low complexity
libdwarf-project CWE-125
7.5
2017-02-17 CVE-2016-5039 Out-of-bounds Read vulnerability in Libdwarf Project Libdwarf
The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.
network
low complexity
libdwarf-project CWE-125
7.5
2017-02-17 CVE-2016-5038 Out-of-bounds Read vulnerability in Libdwarf Project Libdwarf
The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.
network
low complexity
libdwarf-project CWE-125
7.5
2017-02-17 CVE-2016-5036 Out-of-bounds Read vulnerability in Libdwarf Project Libdwarf
The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.
network
low complexity
libdwarf-project CWE-125
7.5
2017-02-17 CVE-2017-6056 Infinite Loop vulnerability in multiple products
It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop.
network
low complexity
canonical debian CWE-835
7.5
2017-02-17 CVE-2017-6014 Infinite Loop vulnerability in multiple products
In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion.
network
low complexity
wireshark debian CWE-835
7.5
2017-02-17 CVE-2017-5012 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Chrome
A heap buffer overflow in V8 in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-119
8.8
2017-02-17 CVE-2017-5009 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Google Chrome
WebRTC in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to perform proper bounds checking, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-119
8.8