- EPSS 25.72%
- Veröffentlicht 08.04.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVE-2016-2851
- EPSS 23.06%
- Veröffentlicht 07.04.2016 23:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-...
CVE-2016-1646
- EPSS 71.72%
- Veröffentlicht 29.03.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...
CVE-2016-3119
- EPSS 5.72%
- Veröffentlicht 26.03.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The process_db_args function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT Kerberos 5 (aka krb5) through 1.13.4 and 1.14.x through 1.14.1 mishandles the DB argument, which allows remote authenticated users...
CVE-2016-1645
- EPSS 2.19%
- Veröffentlicht 13.03.2016 22:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or...
CVE-2016-2802
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:41
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have ...
CVE-2016-2801
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:40
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possi...
CVE-2016-2800
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:39
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecifie...
CVE-2016-2799
- EPSS 1.16%
- Veröffentlicht 13.03.2016 18:59:38
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified...
CVE-2016-2798
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecifi...