CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96266  CVE-2016-9446  Candidate  The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.  Assigned (20161118)  None (candidate not yet proposed)    View
96267  CVE-2016-9447  Candidate  The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.  Assigned (20161118)  None (candidate not yet proposed)    View
96268  CVE-2016-9448  Candidate  The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.  Assigned (20161118)  None (candidate not yet proposed)    View
96269  CVE-2016-9449  Candidate  The taxonomy module in Drupal 7.x before 7.52 and 8.x before 8.2.3 might allow remote authenticated users to obtain sensitive information about taxonomy terms by leveraging inconsistent naming of access query tags.  Assigned (20161118)  None (candidate not yet proposed)    View
96270  CVE-2016-9450  Candidate  The user password reset form in Drupal 8.x before 8.2.3 allows remote attackers to conduct cache poisoning attacks by leveraging failure to specify a correct cache context.  Assigned (20161118)  None (candidate not yet proposed)    View

Page 19254 of 20943, showing 5 records out of 104715 total, starting on record 96266, ending on 96270

Actions