CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-0753
- EPSS 2.33%
- Veröffentlicht 16.02.2016 02:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted para...
CVE-2016-0752
- EPSS 92.71%
- Veröffentlicht 16.02.2016 02:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unre...
CVE-2016-0747
- EPSS 35.5%
- Veröffentlicht 15.02.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
CVE-2016-0746
- EPSS 11.58%
- Veröffentlicht 15.02.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response relate...
CVE-2016-0742
- EPSS 81.25%
- Veröffentlicht 15.02.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2015-8631
- EPSS 1.56%
- Veröffentlicht 13.02.2016 02:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL pr...
CVE-2015-8629
- EPSS 0.68%
- Veröffentlicht 13.02.2016 02:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensit...
CVE-2016-2329
- EPSS 1.16%
- Veröffentlicht 12.02.2016 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified ot...
CVE-2016-1947
- EPSS 0.57%
- Veröffentlicht 31.01.2016 18:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.