CVE-2016-2109
- EPSS 57.94%
- Published 05.05.2016 01:59:05
- Last modified 12.04.2025 10:46:40
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
- EPSS 56.36%
- Published 05.05.2016 01:59:04
- Last modified 12.04.2025 10:46:40
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "ne...
CVE-2016-2107
- EPSS 79.14%
- Published 05.05.2016 01:59:03
- Last modified 12.04.2025 10:46:40
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against...
CVE-2016-2106
- EPSS 63.02%
- Published 05.05.2016 01:59:02
- Last modified 12.04.2025 10:46:40
Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.
CVE-2016-2105
- EPSS 50.8%
- Published 05.05.2016 01:59:01
- Last modified 12.04.2025 10:46:40
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
CVE-2016-0695
- EPSS 2.92%
- Published 21.04.2016 10:59:55
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security.
CVE-2016-0741
- EPSS 2.36%
- Published 19.04.2016 21:59:06
- Last modified 12.04.2025 10:46:40
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.
CVE-2010-5325
- EPSS 5.96%
- Published 15.04.2016 14:59:00
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title.
CVE-2015-8540
- EPSS 13.3%
- Published 14.04.2016 14:59:03
- Last modified 12.04.2025 10:46:40
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...
CVE-2016-3069
- EPSS 2.83%
- Published 13.04.2016 16:59:17
- Last modified 12.04.2025 10:46:40
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.