CVE-2016-7163
- EPSS 0.34%
- Published 21.09.2016 14:25:28
- Last modified 12.04.2025 10:46:40
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
- EPSS 89.58%
- Published 20.09.2016 18:59:00
- Last modified 12.04.2025 10:46:40
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow loc...
CVE-2016-5403
- EPSS 0.07%
- Published 02.08.2016 16:59:03
- Last modified 12.04.2025 10:46:40
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
CVE-2016-5444
- EPSS 4.87%
- Published 21.07.2016 10:14:57
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related...
CVE-2016-5440
- EPSS 0.67%
- Published 21.07.2016 10:14:53
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors relat...
CVE-2016-2775
- EPSS 34.23%
- Published 19.07.2016 22:59:00
- Last modified 12.04.2025 10:46:40
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight reso...
CVE-2016-5388
- EPSS 69.06%
- Published 19.07.2016 02:00:20
- Last modified 12.04.2025 10:46:40
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-5387
- EPSS 77.5%
- Published 19.07.2016 02:00:19
- Last modified 12.04.2025 10:46:40
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an app...
- EPSS 1.2%
- Published 09.06.2016 16:59:06
- Last modified 12.04.2025 10:46:40
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-5126
- EPSS 0.2%
- Published 01.06.2016 22:59:08
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.