CVE-2016-1285
- EPSS 67.84%
- Veröffentlicht 09.03.2016 23:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed...
CVE-2015-8805
- EPSS 1.2%
- Veröffentlicht 23.02.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...
CVE-2015-8804
- EPSS 11.88%
- Veröffentlicht 23.02.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.
CVE-2015-8803
- EPSS 12.34%
- Veröffentlicht 23.02.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown...
- EPSS 3.21%
- Veröffentlicht 21.02.2016 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
CVE-2016-2043
- EPSS 0.39%
- Veröffentlicht 20.02.2016 01:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the ...
CVE-2016-2042
- EPSS 0.58%
- Veröffentlicht 20.02.2016 01:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path ...
CVE-2016-2041
- EPSS 1.03%
- Veröffentlicht 20.02.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restri...
CVE-2016-2040
- EPSS 0.49%
- Veröffentlicht 20.02.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) s...
CVE-2016-2039
- EPSS 0.38%
- Veröffentlicht 20.02.2016 01:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.