Skip to main content

CWE archive

CWE-787 CVEs

Programmatic archive

14,355 CVEs tagged with CWE-7872,491 Critical, 8,810 High, 2,875 Medium, 174 Low, 5 Unrated.

CVE-2016-7127

Published Sep 12, 2016

The imagegammacorrect function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate gamma values, which allows remote attackers to cause a denial o…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7126

Published Sep 12, 2016

The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of colors, which allows remote attackers to ca…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7178

Published Sep 9, 2016

epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5342

Published Aug 30, 2016

Heap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for the Linux kernel 3.x, as used in Qualcom…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4657

Published Aug 25, 2016

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

CVSS 8.8 · High
evidence mentions
8
Buzz score
55.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-4656

Published Aug 25, 2016

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

CVSS 7.8 · High
evidence mentions
8
Buzz score
55.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2016-2065

Published Aug 7, 2016

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1513

Published Aug 5, 2016

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute arbitrary code via crafted Me…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 14,051-14,075 of 14,355 CVEsPage 563 of 575