LiveActive security incident?Get immediate response
CVE archive

January 2016

Browse CVE records published in January 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1112 matching CVEs · Page 15 of 23.

Unknown · CVSS Not scored

CVE-2016-2378: A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin.

A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfiltered malicious user can send negative length values to trigger this vulnerability.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2376: A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin.

A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attacker who intercepts the network traffic can send an invalid size for a packet which will trigger a buffer overflow.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2380: An information leak exists in the handling of the MXIT protocol in Pidgin.

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2367: An information leak exists in the handling of the MXIT protocol in Pidgin.

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2372: An information leak exists in the handling of the MXIT protocol in Pidgin.

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2365: A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin.

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2339: An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functio...

An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.

Published Jan 6, 2017 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2052: Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82...

Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

Published Jan 25, 2016 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2047: The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23,...

The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a "/CN=" string in a field in a certificate, as demonstrated by "/OU=/CN=bar.com/CN=foo.com."

Published Jan 27, 2016 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-2031: Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation...

Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive information, perform unauthorized actions and execute arbitrary code.

Published Jan 31, 2020 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-1903: The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x befor...

The gdImageRotateInterpolated function in ext/gd/libgd/gd_interpolation.c in PHP before 5.5.31, 5.6.x before 5.6.17, and 7.x before 7.0.2 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a large bgd_color argument to the imagerotate function.

Published Jan 19, 2016 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2016-1931: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote atta...

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.

Published Jan 31, 2016 · Updated Aug 5, 2024