Unknown · CVSS Not scored
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite loop) via vectors involving length fields.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
Published Dec 22, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.
Published Dec 13, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to information disclosure.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe InDesign version 11.4.1 and earlier, Adobe InDesign Server 11.0.0 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Experience Manager version 6.2 has an input validation issue in create Launch wizard that could be used in cross-site scripting attacks.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the NetConnection class when handling the proxy types. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe RoboHelp version 2015.0.3 and earlier, RoboHelp 11 and earlier have an input validation issue that could be used in cross-site scripting attacks.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Experience Manager versions 6.2 and earlier have a vulnerability that could be used in Cross-Site Request Forgery attacks.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have security bypass vulnerability in the implementation of the same origin policy.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier have an important vulnerability that could lead to information disclosure.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Experience Manager versions 6.1 and earlier have an input validation issue in the DAM create assets that could be used in cross-site scripting attacks.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class when handling conversion to an object. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the NetConnection class when handling an attached script object. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the PSDK's MediaPlayer class. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the MovieClip class related to objects at multiple presentation levels. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to backtrack search functionality. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability when setting the length property of an array object. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to bookmarking in searches. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable integer overflow vulnerability in the BitmapData class. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class for specific search strategies. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable buffer overflow / underflow vulnerability in the RegExp class related to alternation functionality. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Clipboard class related to data handling functionality. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the PSDK class related to ad policy functionality method. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the Action Message Format serialization (AFM0). Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
Published Dec 15, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.
Published Dec 23, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.
Published Dec 17, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
Published Dec 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Published Dec 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.
Published Dec 29, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.
Published Dec 23, 2016 · Updated Aug 6, 2024