CVE-2016-7445
- EPSS 2.04%
- Veröffentlicht 03.10.2016 16:09:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.
CVE-2016-6172
- EPSS 0.01%
- Veröffentlicht 26.09.2016 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.
CVE-2016-6153
- EPSS 0.03%
- Veröffentlicht 26.09.2016 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by levera...
CVE-2016-5746
- EPSS 0.06%
- Veröffentlicht 26.09.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-...
CVE-2016-4303
- EPSS 5.73%
- Veröffentlicht 26.09.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based b...
CVE-2016-6265
- EPSS 0.5%
- Veröffentlicht 22.09.2016 15:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
CVE-2016-5167
- EPSS 1.75%
- Veröffentlicht 11.09.2016 10:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5166
- EPSS 0.63%
- Veröffentlicht 11.09.2016 10:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly restrict saving a file:// URL that is referenced by an http:// URL, which makes it easier for user-assisted remote...
CVE-2016-5165
- EPSS 0.5%
- Veröffentlicht 11.09.2016 10:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Developer Tools (aka DevTools) subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux allows remote attackers to inject arbitrary web script or HTML via the ...
CVE-2016-5164
- EPSS 0.49%
- Veröffentlicht 11.09.2016 10:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in WebKit/Source/platform/v8_inspector/V8Debugger.cpp in Blink, as used in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to inject arbitrary we...