[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-9446":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-06T08:55:34.825Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":28,"aliases":29,"duplicate_of":9,"upstream":30,"downstream":31,"duplicates":52,"related":53,"reserved_at":9,"published_at":59,"modified_at":60,"state":61,"summary":62,"references_raw":71,"kevs":119,"epss":120,"epss_history":123,"metrics":379,"affected":389},"CVE-2016-9446","The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-665","Improper Initialization","The product does not initialize or incorrectly initializes a resource, which might leave the resource in an unexpected state when it is accessed or used.","weakness","Draft","Class","Medium",[20,24],{"id":21,"name":22,"techniques":23},"CAPEC-26","Leveraging Race Conditions",[],{"id":25,"name":26,"techniques":27},"CAPEC-29","Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions",[],[],[],[],[32,34,36,38,40,42,44,46,48,50],{"_key":33},"SUSE-SU-2016:3296-1",{"_key":35},"SUSE-SU-2016:3297-1",{"_key":37},"SUSE-SU-2017:0027-1",{"_key":39},"SUSE-SU-2017:0028-1",{"_key":41},"DLA-712-1",{"_key":43},"DSA-3717-1",{"_key":45},"MGASA-2018-0012",{"_key":47},"UBUNTU-CVE-2016-9446",{"_key":49},"DEBIAN-CVE-2016-9446",{"_key":51},"RHSA-2017:2060",[],[54,55,56,57,58],{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":45},"2017-01-23T21:00:00.000Z","2024-08-06T02:50:38.682Z","Modified",{"cisa_kev":63,"cisa_ransomware":63,"cisa_vendor":9,"epss_severity":64,"epss_score":65,"severity":66,"severity_score":67,"severity_version":68,"severity_source":69,"severity_vector":70,"severity_status":61},false,"low",0.01283,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",[72,78,84,90,96,100,104,109,114],{"url":73,"sources":74,"tags":76},"https://bugzilla.gnome.org/show_bug.cgi?id=774533",[75,69],"cve.org",[77],"X Refsource CONFIRM",{"url":79,"sources":80,"tags":81},"http://www.openwall.com/lists/oss-security/2016/11/18/13",[75,69],[82,83],"Mailing List","X Refsource MLIST",{"url":85,"sources":86,"tags":87},"http://www.securityfocus.com/bid/94423",[75,69],[88,89],"VDB Entry","X Refsource BID",{"url":91,"sources":92,"tags":93},"https://access.redhat.com/errata/RHSA-2017:2060",[75,69],[94,95],"Vendor Advisory","X Refsource REDHAT",{"url":97,"sources":98,"tags":99},"https://cgit.freedesktop.org/gstreamer/gst-plugins-bad/commit/gst/vmnc/vmncdec.c?id=4cb1bcf1422bbcd79c0f683edb7ee85e3f7a31fe",[75,69],[77],{"url":101,"sources":102,"tags":103},"http://www.openwall.com/lists/oss-security/2016/11/18/12",[75,69],[82,83],{"url":105,"sources":106,"tags":107},"https://scarybeastsecurity.blogspot.de/2016/11/0day-poc-risky-design-decisions-in.html",[75,69],[108],"X Refsource MISC",{"url":110,"sources":111,"tags":112},"https://security.gentoo.org/glsa/201705-10",[75,69],[94,113],"X Refsource GENTOO",{"url":115,"sources":116,"tags":117},"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UM7IXFGHV66KNWGWG6ZBDNKXD2UJL2VQ/",[75,69],[94,118],"X Refsource FEDORA",[],{"date":121,"score":65,"percentile":122},"2026-06-05",0.79964,[124,127,129,132,135,138,141,143,146,149,152,155,157,160,163,166,169,172,175,178,181,184,187,190,193,195,198,201,204,207,210,212,215,218,220,223,226,229,232,235,237,240,242,244,247,250,253,256,258,261,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,307,310,313,316,319,321,324,327,329,332,335,338,341,344,347,350,353,356,359,362,365,367,370,373,376],{"date":125,"score":65,"percentile":126},"2025-11-04",0.78941,{"date":128,"score":65,"percentile":126},"2025-11-05",{"date":130,"score":65,"percentile":131},"2025-11-06",0.78939,{"date":133,"score":65,"percentile":134},"2025-11-07",0.78952,{"date":136,"score":65,"percentile":137},"2025-11-08",0.78957,{"date":139,"score":65,"percentile":140},"2025-11-09",0.78951,{"date":142,"score":65,"percentile":131},"2025-11-10",{"date":144,"score":65,"percentile":145},"2025-11-11",0.78942,{"date":147,"score":65,"percentile":148},"2025-11-12",0.78959,{"date":150,"score":65,"percentile":151},"2025-11-13",0.78968,{"date":153,"score":65,"percentile":154},"2025-11-14",0.78975,{"date":156,"score":65,"percentile":154},"2025-11-15",{"date":158,"score":65,"percentile":159},"2025-11-16",0.78976,{"date":161,"score":65,"percentile":162},"2025-11-17",0.7897,{"date":164,"score":65,"percentile":165},"2025-11-18",0.77854,{"date":167,"score":65,"percentile":168},"2025-11-19",0.7786,{"date":170,"score":65,"percentile":171},"2025-11-20",0.77867,{"date":173,"score":65,"percentile":174},"2025-11-21",0.78993,{"date":176,"score":65,"percentile":177},"2025-11-22",0.78995,{"date":179,"score":65,"percentile":180},"2025-11-23",0.78983,{"date":182,"score":65,"percentile":183},"2025-11-24",0.78981,{"date":185,"score":65,"percentile":186},"2025-11-25",0.78986,{"date":188,"score":65,"percentile":189},"2025-11-26",0.78987,{"date":191,"score":65,"percentile":192},"2025-11-27",0.78989,{"date":194,"score":65,"percentile":183},"2025-11-28",{"date":196,"score":65,"percentile":197},"2025-11-29",0.7899,{"date":199,"score":65,"percentile":200},"2025-11-30",0.78988,{"date":202,"score":65,"percentile":203},"2025-12-01",0.79079,{"date":205,"score":65,"percentile":206},"2025-12-02",0.79081,{"date":208,"score":65,"percentile":209},"2025-12-03",0.79082,{"date":211,"score":65,"percentile":192},"2025-12-04",{"date":213,"score":65,"percentile":214},"2025-12-05",0.78994,{"date":216,"score":65,"percentile":217},"2025-12-06",0.78997,{"date":219,"score":65,"percentile":217},"2025-12-07",{"date":221,"score":65,"percentile":222},"2025-12-08",0.79002,{"date":224,"score":65,"percentile":225},"2025-12-09",0.79018,{"date":227,"score":65,"percentile":228},"2025-12-10",0.7904,{"date":230,"score":65,"percentile":231},"2025-12-11",0.79054,{"date":233,"score":65,"percentile":234},"2025-12-12",0.79074,{"date":236,"score":65,"percentile":234},"2025-12-13",{"date":238,"score":65,"percentile":239},"2025-12-14",0.79071,{"date":241,"score":65,"percentile":239},"2025-12-15",{"date":243,"score":65,"percentile":209},"2025-12-16",{"date":245,"score":65,"percentile":246},"2025-12-17",0.79088,{"date":248,"score":65,"percentile":249},"2025-12-18",0.79108,{"date":251,"score":65,"percentile":252},"2025-12-19",0.79119,{"date":254,"score":65,"percentile":255},"2025-12-20",0.79114,{"date":257,"score":65,"percentile":249},"2025-12-21",{"date":259,"score":65,"percentile":260},"2025-12-22",0.7911,{"date":262,"score":65,"percentile":260},"2025-12-23",{"date":264,"score":65,"percentile":265},"2025-12-24",0.79124,{"date":267,"score":65,"percentile":268},"2025-12-25",0.79143,{"date":270,"score":65,"percentile":271},"2025-12-26",0.7914,{"date":273,"score":65,"percentile":274},"2025-12-27",0.79189,{"date":276,"score":65,"percentile":277},"2025-12-28",0.7913,{"date":279,"score":65,"percentile":280},"2025-12-29",0.79125,{"date":282,"score":65,"percentile":283},"2025-12-30",0.79133,{"date":285,"score":65,"percentile":286},"2025-12-31",0.79149,{"date":288,"score":65,"percentile":289},"2026-01-01",0.79244,{"date":291,"score":65,"percentile":292},"2026-01-02",0.79242,{"date":294,"score":65,"percentile":295},"2026-01-03",0.79239,{"date":297,"score":65,"percentile":298},"2026-01-04",0.79141,{"date":300,"score":65,"percentile":301},"2026-01-05",0.79137,{"date":303,"score":65,"percentile":304},"2026-01-06",0.79142,{"date":306,"score":65,"percentile":286},"2026-01-07",{"date":308,"score":65,"percentile":309},"2026-01-08",0.7916,{"date":311,"score":65,"percentile":312},"2026-01-09",0.79162,{"date":314,"score":65,"percentile":315},"2026-01-10",0.79163,{"date":317,"score":65,"percentile":318},"2026-01-11",0.79158,{"date":320,"score":65,"percentile":268},"2026-01-12",{"date":322,"score":65,"percentile":323},"2026-01-13",0.79139,{"date":325,"score":65,"percentile":326},"2026-01-14",0.79161,{"date":328,"score":65,"percentile":312},"2026-01-15",{"date":330,"score":65,"percentile":331},"2026-01-16",0.79168,{"date":333,"score":65,"percentile":334},"2026-01-17",0.79178,{"date":336,"score":65,"percentile":337},"2026-01-18",0.79174,{"date":339,"score":65,"percentile":340},"2026-01-19",0.79167,{"date":342,"score":65,"percentile":343},"2026-01-20",0.79165,{"date":345,"score":65,"percentile":346},"2026-01-21",0.79171,{"date":348,"score":65,"percentile":349},"2026-01-22",0.79182,{"date":351,"score":65,"percentile":352},"2026-01-23",0.79209,{"date":354,"score":65,"percentile":355},"2026-01-24",0.79219,{"date":357,"score":65,"percentile":358},"2026-01-25",0.79212,{"date":360,"score":65,"percentile":361},"2026-01-26",0.79208,{"date":363,"score":65,"percentile":364},"2026-01-27",0.79207,{"date":366,"score":65,"percentile":364},"2026-01-28",{"date":368,"score":65,"percentile":369},"2026-01-29",0.79204,{"date":371,"score":65,"percentile":372},"2026-01-30",0.79206,{"date":374,"score":65,"percentile":375},"2026-01-31",0.7921,{"date":377,"score":65,"percentile":378},"2026-02-01",0.79306,[380],{"source":69,"cvss_v2_0":381,"cvss_v3_0":9,"cvss_v3_1":386,"cvss_v4_0":9},{"baseScore":382,"baseSeverity":9,"vectorString":383,"impactScore":384,"exploitabilityScore":385},5,"AV:N/AC:L/Au:N/C:P/I:N/A:N",2.9,10,{"baseScore":67,"baseSeverity":387,"vectorString":70,"impactScore":388,"exploitabilityScore":385},"HIGH",6,[390,398,408,411,418,430,435,442,448],{"ecosystem":9,"name":391,"vendor":392,"product":391,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":394},"fedora","fedoraproject","o",[395],{"version":396,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"35","cpe",{"ecosystem":9,"name":399,"vendor":400,"product":399,"cpe_part":401,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":402},"gstreamer","gstreamer_project","a",[403],{"version":404,"is_range":405,"range_type":397,"version_start":9,"version_start_type":9,"version_end":406,"version_end_type":407,"fixed_in":9},"lt1.11.1",true,"1.11.1","excluding",{"ecosystem":9,"name":399,"vendor":399,"product":399,"cpe_part":401,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":409},[410],{"version":404,"is_range":405,"range_type":397,"version_start":9,"version_start_type":9,"version_end":406,"version_end_type":407,"fixed_in":9},{"ecosystem":9,"name":412,"vendor":413,"product":414,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":415},"enterprise linux desktop","redhat","enterprise_linux_desktop",[416],{"version":417,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0",{"ecosystem":9,"name":419,"vendor":413,"product":420,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":421},"enterprise linux eus","enterprise_linux_eus",[422,424,426,428],{"version":423,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.4",{"version":425,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.5",{"version":427,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.6",{"version":429,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.7",{"ecosystem":9,"name":431,"vendor":413,"product":432,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":433},"enterprise linux server","enterprise_linux_server",[434],{"version":417,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":436,"vendor":413,"product":437,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":438},"enterprise linux server aus","enterprise_linux_server_aus",[439,440,441],{"version":423,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":427,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":429,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":443,"vendor":413,"product":444,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":445},"enterprise linux server tus","enterprise_linux_server_tus",[446,447],{"version":427,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":429,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"ecosystem":9,"name":449,"vendor":413,"product":450,"cpe_part":393,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":451},"enterprise linux workstation","enterprise_linux_workstation",[452],{"version":417,"is_range":63,"range_type":397,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9}]