CVE-2015-8872
- EPSS 0.08%
- Veröffentlicht 03.06.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesys...
CVE-2016-1234
- EPSS 1.18%
- Veröffentlicht 01.06.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
CVE-2016-0718
- EPSS 1.5%
- Veröffentlicht 26.05.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
CVE-2016-4049
- EPSS 2.16%
- Veröffentlicht 23.05.2016 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP packet.
CVE-2016-3959
- EPSS 2.47%
- Veröffentlicht 23.05.2016 19:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted pub...
CVE-2016-4578
- EPSS 0.2%
- Veröffentlicht 23.05.2016 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_t...
CVE-2016-4544
- EPSS 3.94%
- Veröffentlicht 22.05.2016 01:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...
CVE-2016-4543
- EPSS 4.08%
- Veröffentlicht 22.05.2016 01:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have uns...
CVE-2016-4542
- EPSS 1.23%
- Veröffentlicht 22.05.2016 01:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or po...
CVE-2016-4541
- EPSS 1.43%
- Veröffentlicht 22.05.2016 01:59:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact vi...