Skip to main content

CWE archive

CWE-190 CVEs

Programmatic archive

3,302 CVEs tagged with CWE-190432 Critical, 1,919 High, 852 Medium, 97 Low, 2 Unrated.

CVE-2017-7885

Published Apr 17, 2017

Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7603

Published Apr 9, 2017

au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7602

Published Apr 9, 2017

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a cr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0576

Published Apr 7, 2017

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel.…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0553

Published Apr 7, 2017

An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8795

Published Apr 2, 2017

Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V100R002C00, V100R003C00, V100R…

CVSS 5.9 · Medium

CVE-2017-7395

Published Apr 1, 2017

In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7294

Published Mar 29, 2017

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of certain levels data, which allows…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9123

Published Mar 28, 2017

go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5931

Published Mar 27, 2017

Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly exe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9557

Published Mar 23, 2017

Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9387

Published Mar 23, 2017

Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, wh…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9262

Published Mar 23, 2017

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6839

Published Mar 20, 2017

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6838

Published Mar 20, 2017

Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8983

Published Mar 20, 2017

Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6962

Published Mar 17, 2017

An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is related to the read_chunk function making an unchecked add…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6952

Published Mar 16, 2017

Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 3,001-3,025 of 3,302 CVEsPage 121 of 133