CVE-2015-3405
- EPSS 6.21%
- Veröffentlicht 09.08.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remot...
CVE-2016-9675
- EPSS 0.8%
- Veröffentlicht 22.12.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
CVE-2016-5009
- EPSS 1.36%
- Veröffentlicht 12.07.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CVE-2016-2818
- EPSS 0.59%
- Veröffentlicht 13.06.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
- EPSS 9.38%
- Veröffentlicht 22.10.2015 00:00:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
CVE-2015-3214
- EPSS 1.47%
- Veröffentlicht 31.08.2015 10:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an inva...
CVE-2015-5165
- EPSS 10.86%
- Veröffentlicht 12.08.2015 14:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
- EPSS 90.11%
- Veröffentlicht 25.09.2014 01:55:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted enviro...
- EPSS 94.22%
- Veröffentlicht 24.09.2014 18:48:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceComman...
CVE-2013-1675
- EPSS 2.57%
- Veröffentlicht 16.05.2013 11:45:30
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale funct...