Skip to main content

CWE archive

CWE-416 CVEs

Programmatic archive

7,941 CVEs tagged with CWE-416819 Critical, 5,735 High, 1,272 Medium, 115 Low, 0 Unrated.

CVE-2016-6892

Published Jan 5, 2017

The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a crafted X.509 certificate.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9936

Published Jan 4, 2017

The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified ot…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9138

Published Jan 4, 2017

PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9137

Published Jan 4, 2017

Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10088

Published Dec 30, 2016

The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9794

Published Dec 28, 2016

Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9576

Published Dec 28, 2016

The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9923

Published Dec 23, 2016

Quick Emulator (Qemu) built with the 'chardev' backend support is vulnerable to a use after free issue. It could occur while hotplug and unplugging the device in the guest. A gues…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5190

Published Dec 18, 2016

Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles during shutdown, which allowed a remote attacker to…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5185

Published Dec 18, 2016

Blink in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly allowed reentrance of FrameView::updateLifecyclePhasesInternal(), wh…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5184

Published Dec 18, 2016

PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled object lifecycles in CFFL_FormFillter::KillFocusForAnnot, w…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5183

Published Dec 18, 2016

A heap use after free in PDFium in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android allows a remote attacker to potentially exploit heap c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 7,476-7,500 of 7,941 CVEsPage 300 of 318