CVE-2016-4300
- EPSS 1.77%
- Published 21.09.2016 14:25:01
- Last modified 12.04.2025 10:46:40
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buf...
- EPSS 89.58%
- Published 20.09.2016 18:59:00
- Last modified 12.04.2025 10:46:40
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow loc...
CVE-2016-5403
- EPSS 0.07%
- Published 02.08.2016 16:59:03
- Last modified 12.04.2025 10:46:40
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
CVE-2016-5444
- EPSS 4.87%
- Published 21.07.2016 10:14:57
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related...
CVE-2016-5440
- EPSS 0.67%
- Published 21.07.2016 10:14:53
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors relat...
CVE-2016-2775
- EPSS 34.23%
- Published 19.07.2016 22:59:00
- Last modified 12.04.2025 10:46:40
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight reso...
CVE-2016-5388
- EPSS 69.06%
- Published 19.07.2016 02:00:20
- Last modified 12.04.2025 10:46:40
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-5387
- EPSS 77.5%
- Published 19.07.2016 02:00:19
- Last modified 12.04.2025 10:46:40
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an app...
CVE-2016-5386
- EPSS 87.62%
- Published 19.07.2016 02:00:18
- Last modified 12.04.2025 10:46:40
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which mi...
CVE-2016-4470
- EPSS 0.06%
- Published 27.06.2016 10:59:08
- Last modified 12.04.2025 10:46:40
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...