Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-02-03 CVE-2016-3183 Out-of-bounds Read vulnerability in Uclouvain Openjpeg
The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg2000 file.
local
low complexity
uclouvain CWE-125
5.5
2017-02-03 CVE-2016-9642 Out-of-bounds Read vulnerability in Webkit
JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.
local
low complexity
webkit CWE-125
5.5
2017-02-03 CVE-2016-9082 Integer Overflow or Wraparound vulnerability in Cairographics Cairo 1.14.6
Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.
local
low complexity
cairographics CWE-190
5.5
2017-02-03 CVE-2016-8569 NULL Pointer Dereference vulnerability in multiple products
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
5.5
2017-02-03 CVE-2016-8568 Out-of-bounds Read vulnerability in multiple products
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
5.5
2017-02-03 CVE-2016-6163 Out-of-bounds Read vulnerability in Gnome Librsvg 2.40.2
The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
local
low complexity
gnome CWE-125
5.5
2017-02-03 CVE-2016-5241 Numeric Errors vulnerability in multiple products
magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.
local
low complexity
graphicsmagick debian opensuse CWE-189
5.5
2017-02-03 CVE-2016-5115 Out-of-bounds Read vulnerability in Libavformat Project Libavformat 57.34.103
The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
local
low complexity
libavformat-project CWE-125
5.5
2017-02-03 CVE-2016-4571 Resource Exhaustion vulnerability in multiple products
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
local
low complexity
mini-xml-project debian CWE-400
5.5
2017-02-03 CVE-2016-4570 Resource Exhaustion vulnerability in multiple products
The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
local
low complexity
mini-xml-project debian CWE-400
5.5