CVE-2016-2039
- EPSS 0.38%
- Veröffentlicht 20.02.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.
CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-0753
- EPSS 2.33%
- Veröffentlicht 16.02.2016 02:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted para...
CVE-2016-0752
- EPSS 91.05%
- Veröffentlicht 16.02.2016 02:59:06
- Zuletzt bearbeitet 22.04.2026 14:36:55
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unre...
CVE-2016-0747
- EPSS 20.44%
- Veröffentlicht 15.02.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
CVE-2016-0746
- EPSS 6.51%
- Veröffentlicht 15.02.2016 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response relate...
CVE-2016-0742
- EPSS 79.08%
- Veröffentlicht 15.02.2016 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2015-8631
- EPSS 2.21%
- Veröffentlicht 13.02.2016 02:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL pr...
CVE-2015-8629
- EPSS 1.61%
- Veröffentlicht 13.02.2016 02:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensit...
CVE-2016-2329
- EPSS 1.16%
- Veröffentlicht 12.02.2016 05:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified ot...