NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
20461  CVE-2016-5114  sapi/fpm/fpm/fpm_log.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 misinterprets the semantics of the snprintf return value, which allows attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and buffer overflow) via a long string, as demonstrated by a long URI in a configuration with custom REQUEST_URI logging.    6.4  Medium  2017-01-19  2016-08-23  View
81774  CVE-2016-5115  The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.    4.3  Medium  2017-02-08  2017-02-07  View
20462  CVE-2016-5116  gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.    6.4  Medium  2017-01-19  2016-11-28  View
81775  CVE-2016-5117  OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp constraint with a valid certificate.    4.3  Medium  2017-02-28  2017-02-24  View
20463  CVE-2016-5118  The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.    10  High  2017-01-19  2017-01-03  View

Page 16058 of 17672, showing 5 records out of 88360 total, starting on record 80286, ending on 80290

Actions