CVE-2016-5444
- EPSS 3.81%
- Veröffentlicht 21.07.2016 10:14:57
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related...
CVE-2016-3471
- EPSS 0.09%
- Veröffentlicht 21.07.2016 10:12:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Option.
CVE-2016-3452
- EPSS 3.27%
- Veröffentlicht 21.07.2016 10:12:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related...
CVE-2016-6170
- EPSS 13.02%
- Veröffentlicht 06.07.2016 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of ser...
CVE-2016-5244
- EPSS 0.58%
- Veröffentlicht 27.06.2016 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-2150
- EPSS 0.07%
- Veröffentlicht 09.06.2016 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
- EPSS 33.85%
- Veröffentlicht 09.06.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
CVE-2016-4805
- EPSS 0.15%
- Veröffentlicht 23.05.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a n...
CVE-2015-4644
- EPSS 9.89%
- Veröffentlicht 16.05.2016 10:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
The php_pgsql_meta_data function in pgsql.c in the PostgreSQL (aka pgsql) extension in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not validate token extraction for table names, which might allow remote attackers to cause a d...