Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-01 CVE-2016-9825 Numeric Errors vulnerability in Libav 11.8
libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
local
low complexity
libav CWE-189
5.5
2017-03-01 CVE-2016-9824 Integer Overflow or Wraparound vulnerability in Libav 11.8
Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
libav CWE-190
5.5
2017-03-01 CVE-2016-9823 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Libav 11.8
libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
libav CWE-119
5.5
2017-03-01 CVE-2016-9822 Integer Overflow or Wraparound vulnerability in Libav 11.8
Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
libav CWE-190
5.5
2017-03-01 CVE-2016-9821 Integer Overflow or Wraparound vulnerability in Libav 11.8
Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
local
low complexity
libav CWE-190
5.5
2017-03-01 CVE-2016-9820 Numeric Errors vulnerability in Libav 11.8
libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
local
low complexity
libav CWE-189
5.5
2017-03-01 CVE-2016-9819 Numeric Errors vulnerability in Libav 11.8
libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
local
low complexity
libav CWE-189
5.5
2017-03-01 CVE-2016-9559 NULL Pointer Dereference vulnerability in multiple products
coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image.
network
low complexity
imagemagick debian CWE-476
6.5
2017-03-01 CVE-2016-8508 7PK - Security Features vulnerability in Yandex Browser
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
network
low complexity
yandex CWE-254
6.5
2017-03-01 CVE-2016-8507 Information Exposure vulnerability in Yandex Browser
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
network
low complexity
yandex CWE-200
6.5