Skip to main content

CWE archive

CWE-787 CVEs

Programmatic archive

14,359 CVEs tagged with CWE-7872,492 Critical, 8,815 High, 2,875 Medium, 174 Low, 3 Unrated.

CVE-2016-7161

Published Oct 5, 2016

Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large e…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3624

Published Oct 3, 2016

The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) by setting the "-v" option to -…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5270

Published Sep 22, 2016

Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-3991

Published Sep 21, 2016

Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3990

Published Sep 21, 2016

Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (crash) or exe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3945

Published Sep 21, 2016

Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attacker…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3632

Published Sep 21, 2016

The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6303

Published Sep 16, 2016

Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and applic…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 14,026-14,050 of 14,359 CVEsPage 562 of 575