CVE-2012-6303 – WaveSurfer 1.8.8p4 - Memory Corruption (PoC)
https://notcve.org/view.php?id=CVE-2012-6303
Heap-based buffer overflow in the GetWavHeader function in generic/jkSoundFile.c in the Snack Sound Toolkit, as used in WaveSurfer 1.8.8p4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large chunk size in a WAV file. Desbordamiento de buffer basado en memoria dinámica en la función GetWavHeader en generic/jkSoundfile.c en Snack Sound Toolkit, usado en WaveSurfer 1.8.8p4, permite a atacantes remotos causar denegación de servicio (caída) y posiblemente ejecutar código arbitrario a través de fragmentos de gran tamaño en un fichero WAV. • https://www.exploit-db.com/exploits/19772 http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00034.html http://secunia.com/advisories/49889 http://security.gentoo.org/glsa/glsa-201309-04.xml http://www.exploit-db.com/exploits/19772 http://www.mandriva.com/security/advisories?name=MDVSA-2013:126 http://www.openwall.com/lists/oss-security/2012/12/10/2 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2012-4540 – icedtea-web: IcedTeaScriptableJavaObject:: invoke off-by-one heap-based buffer overflow
https://notcve.org/view.php?id=CVE-2012-4540
Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.x before 1.4.1 allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly execute arbitrary code via a crafted webpage that triggers a heap-based buffer overflow, related to an error message and a "triggering event attached to applet." NOTE: the 1.4.x versions were originally associated with CVE-2013-4349, but that entry has been MERGED with this one. Error off-by-one en la función de invoke en IcedTeaScriptablePluginObject.cc en IcedTea-Web v1.1.x antes de v1.1.7, v1.2.x antes de v1.2.2, y v1.3.x antes de v1.3.1, permite a atacantes remotos obtener información sensible, provocar una denegación de servicio (caída) o posiblemente ejecutar código arbitrario a través de una página web diseñada que provoca un desbordamiento de búfer basado en memoria dinámica, en relación con un mensaje de error y un "evento desencadenante unido a applet." • http://icedtea.classpath.org/hg/release/icedtea-web-1.1/file/d759ec560073/NEWS http://icedtea.classpath.org/hg/release/icedtea-web-1.2/rev/596a718be03f http://icedtea.classpath.org/hg/release/icedtea-web-1.3/rev/e7970f3da5fe http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00019.html http://lists.opensuse.org/opensuse-updates/2012-11/msg00040.html http://lists.opensuse.org/opensuse-updates/2013-01/msg00065.html http://lists.opensuse.org/opensuse-updates/2013-09/msg00071.html • CWE-122: Heap-based Buffer Overflow CWE-189: Numeric Errors •
CVE-2012-4183 – Mozilla: Use-after-free, buffer overflow, and out of bounds read issues found using Address Sanitizer (MFSA 2012-85)
https://notcve.org/view.php?id=CVE-2012-4183
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors. Vulnerabilidad de uso después de liberación en la función DOMSVGTests::GetRequiredFeatures en Mozilla Firefox v16.0, Firefox ESR v10.x antes de v10.0.8, Thunderbird antes de v16.0, Thunderbird ESR v10.x antes de v10.0.8, y SeaMonkey antes de v2.13, permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria dinámica) a través de vectores no especificados. • http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00010.html http://osvdb.org/86095 http://rhn.redhat.com/errata/RHSA-2012-1351.html http://secunia.com/advisories/50856 http://secunia.com/advisories/50892 http://secunia.com/advisories/50904 http://secunia.com/advisories/50935 http://secunia.com/advisories/50936 http://secunia.com/advisories/50984 http://secunia.com/advisories/55318 http://www.mandriva.com/security/advisories?name=MDVSA-2012:163 http://www. • CWE-125: Out-of-bounds Read CWE-416: Use After Free •
CVE-2011-3079
https://notcve.org/view.php?id=CVE-2011-3079
The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors. La implementación de Inter-process Communication (IPC) en Google Chrome en versiones anteriores a 18.0.1025.168, tal como se utiliza en Mozilla Firefox en versiones anteriores a 38.0 y otros productos, no valida mensajes adecuadamente, lo que tiene un impacto y vectores de ataque no especificados. • http://code.google.com/p/chromium/issues/detail?id=117627 http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.html http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html http://osvdb.org/81645 http://rhn.redhat.com/errata/RHSA-2015-1012.html http://secunia.com/advisories/48992 http://www.debian.org/securi • CWE-399: Resource Management Errors •
CVE-2009-1364 – libwmf: embedded gd use-after-free error
https://notcve.org/view.php?id=CVE-2009-1364
Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file. vulnerabilidad de uso después de liberación (use-after-free) en la librería incrustada GD en libwmf v0.2.8.4 permite a atacantes dependiendo del contexto causar una denegación de servicio (cuelgue de aplicación) o posiblemente ejecutar código a su elección a través de un archivo WMF elaborado. • http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html http://lists.opensuse.org/opensuse-updates/2015-06/msg00051.html http://lists.opensuse.org/opensuse-updates/2015-06/msg00053.html http://rhn.redhat.com/errata/RHSA-2009-0457.html http://secunia.com/advisories/34901 http://secunia.com/advisories/34964 http://secunia.com/advisories/35001 http://secunia.com/advisories/35025 http://secunia.com/advisories/35190 http://secunia.com/advisories/35416 http://secuni • CWE-416: Use After Free •