CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96624  CVE-2016-9804  Candidate  In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "frm->ptr" parameter. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.  Assigned (20161203)  None (candidate not yet proposed)    View
96625  CVE-2016-9805  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161203)  None (candidate not yet proposed)    View
96626  CVE-2016-9806  Candidate  Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.  Assigned (20161204)  None (candidate not yet proposed)    View
96627  CVE-2016-9807  Candidate  The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.  Assigned (20161204)  None (candidate not yet proposed)    View
96628  CVE-2016-9808  Candidate  The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.  Assigned (20161204)  None (candidate not yet proposed)    View

Page 19289 of 20943, showing 5 records out of 104715 total, starting on record 96441, ending on 96445

Actions