CVE-2016-5388
- EPSS 69.06%
- Veröffentlicht 19.07.2016 02:00:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh...
CVE-2016-5387
- EPSS 77.5%
- Veröffentlicht 19.07.2016 02:00:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an app...
CVE-2016-5385
- EPSS 84.16%
- Veröffentlicht 19.07.2016 02:00:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attacker...
CVE-2016-5009
- EPSS 1.36%
- Veröffentlicht 12.07.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.
CVE-2016-1704
- EPSS 0.8%
- Veröffentlicht 03.07.2016 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-0758
- EPSS 0.2%
- Veröffentlicht 27.06.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
- EPSS 24.52%
- Veröffentlicht 16.06.2016 14:59:51
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.
CVE-2016-4156
- EPSS 6.25%
- Veröffentlicht 16.06.2016 14:59:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs...
CVE-2016-4155
- EPSS 4.13%
- Veröffentlicht 16.06.2016 14:59:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs...