CVE-2016-10190
published 2017-02-09CVE-2016-10190: Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web…
PriorityP356critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
8.36%
94.3th percentile
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:3.2.2-1 (bookworm) | ffmpeg 7:3.2.2-1 (bookworm) |
| ffmpeg | ffmpeg | <= 2.8.9 | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:3.2.2-1 | 7:3.2.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.2.2-1 | 7:3.2.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.2.2-1 | 7:3.2.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.2.2-1 | 7:3.2.2-1 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-10190: ffmpeg - Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x ...
vendor_debian·2016·CVSS 9.8
CVE-2016-10190 [CRITICAL] CVE-2016-10190: ffmpeg - Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x ...
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
Scope: local
bookworm: resolved (fixed in 7:3.2.2-1)
bullseye: resolved (fixed in 7:3.2.2-1)
forky: resolved (fixed in 7:3.2.2-1)
sid: resolved (fixed in 7:3.2.2-1)
trixie: resolved (fixed in 7:3.2.2-1)
GHSA
GHSA-2x24-gfqp-9jhx: Heap-based buffer overflow in libavformat/http
ghsa_unreviewed·2022-05-14
CVE-2016-10190 [CRITICAL] CWE-119 GHSA-2x24-gfqp-9jhx: Heap-based buffer overflow in libavformat/http
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
OSV
CVE-2016-10190: Heap-based buffer overflow in libavformat/http
osv·2017-02-09·CVSS 9.8
CVE-2016-10190 [CRITICAL] CVE-2016-10190: Heap-based buffer overflow in libavformat/http
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.
No detection rules found.
No public exploits indexed.
arXiv
Graph Neural Networks for Vulnerability Detection: A Counterfactual Explanation
arxiv_fulltext·2024-07-15
Graph Neural Networks for Vulnerability Detection: A Counterfactual Explanation
[Graph Neural Networks for Vulnerability Detection: A Counterfactual Explanation]Graph Neural Networks for Vulnerability Detection:
A Counterfactual Explanation
## Abstract
Vulnerability detection is crucial for ensuring the security and reliability of software systems.
Recently, Graph Neural Networks (GNNs) have emerged as a prominent code embedding approach for vulnerability detection, owing to their ability to capture the underlying semantic structure of source code.
However, GNNs face significant challenges in explainability due to their inherently black-box nature.
To this end, several factual reasoning-based explainers have been proposed.
These explainers provide explanations for the predictions made by GNNs by analyzing the key features that contribute to the outcomes.
We argue t
arXiv
ReCFA: Resilient Control-Flow Attestation
arxiv_fulltext·2021-12-11
ReCFA: Resilient Control-Flow Attestation
ReCFA: Resilient Control-Flow Attestation
Yumei Zhang
Both authors contributed equally to this research and are co-first authors.
[email protected]
Xinzhi Liu
[1]
[email protected]
Xidian University
Xi'an
China
710071
Cong Sun
Corresponding author
[email protected]
0000-0001-9116-2694
Xidian University
Xi'an
China
710071
Dongrui Zeng
[email protected]
Pennsylvania State University
University Park
PA
USA
Gang Tan
[email protected]
Pennsylvania State University
University Park
PA
USA
Xiao Kan
[email protected]
Xidian University
Xi'an
China
710071
Siqi Ma
[email protected]
The University of Queensland
Brisbane
Australia
## Abstract
Recent IoT applications gradually adapt more complicated end systems with commodity software. Ensuring the runtime integrity of these software is a c
http://www.openwall.com/lists/oss-security/2017/01/31/12http://www.openwall.com/lists/oss-security/2017/02/02/1http://www.securityfocus.com/bid/95986https://ffmpeg.org/security.htmlhttps://github.com/FFmpeg/FFmpeg/commit/2a05c8f813de6f2278827734bf8102291e7484aahttps://lists.debian.org/debian-lts-announce/2018/12/msg00009.htmlhttps://trac.ffmpeg.org/ticket/5992http://www.openwall.com/lists/oss-security/2017/01/31/12http://www.openwall.com/lists/oss-security/2017/02/02/1http://www.securityfocus.com/bid/95986https://ffmpeg.org/security.htmlhttps://github.com/FFmpeg/FFmpeg/commit/2a05c8f813de6f2278827734bf8102291e7484aahttps://lists.debian.org/debian-lts-announce/2018/12/msg00009.htmlhttps://trac.ffmpeg.org/ticket/5992
2017-02-09
Published