Skip to main content

CWE archive

CWE-252 CVEs

Programmatic archive

174 CVEs tagged with CWE-25210 Critical, 67 High, 85 Medium, 12 Low, 0 Unrated.

CVE-2020-6078

Published Mar 24, 2020

An exploitable denial-of-service vulnerability exists in the message-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing mDNS messages in mdns_recv, the return valu…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-15900

Published Oct 18, 2019

An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. In…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9372

Published Sep 27, 2019

In libskia, there is a possible crash due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15942

Published Sep 5, 2019

FFmpeg through 4.2 has a "Conditional jump or move depends on uninitialised value" issue in h2645_parse because alloc_rbsp_buffer in libavcodec/h2645_parse.c mishandles rbsp_buffe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12107

Published May 15, 2019

The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snpri…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14622

Published Aug 30, 2018

A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a…

CVSS 7.5 · High

CVE-2018-14367

Published Jul 19, 2018

In Wireshark 2.6.0 to 2.6.1 and 2.4.0 to 2.4.7, the CoAP protocol dissector could crash. This was addressed in epan/dissectors/packet-coap.c by properly checking for a NULL condit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0774

Published Sep 8, 2017

A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-62…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0720

Published Aug 9, 2017

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0599

Published May 12, 2017

A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10061

Published Mar 3, 2017

The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10060

Published Mar 2, 2017

The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to ca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0265

Published Jan 26, 2009

Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-174 of 174 CVEsPage 7 of 7