CVE-2016-2775
- EPSS 43.3%
- Veröffentlicht 19.07.2016 22:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight reso...
CVE-2016-5388
- EPSS 36.76%
- Veröffentlicht 19.07.2016 02:00:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-5387
- EPSS 60.28%
- Veröffentlicht 19.07.2016 02:00:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an app...
CVE-2016-5386
- EPSS 45.9%
- Veröffentlicht 19.07.2016 02:00:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which mi...
CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-0758
- EPSS 0.15%
- Veröffentlicht 27.06.2016 10:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
CVE-2016-3698
- EPSS 2.06%
- Veröffentlicht 13.06.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity d...
CVE-2016-2818
- EPSS 0.29%
- Veröffentlicht 13.06.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
- EPSS 1.55%
- Veröffentlicht 09.06.2016 16:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-2150
- EPSS 0.07%
- Veröffentlicht 09.06.2016 16:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.