CVE-2016-2313
- EPSS 1.08%
- Published 13.04.2016 17:59:11
- Last modified 12.04.2025 10:46:40
auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database.
CVE-2016-0787
- EPSS 2.3%
- Published 13.04.2016 17:59:10
- Last modified 12.04.2025 10:46:40
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes...
CVE-2016-3982
- EPSS 1.7%
- Published 13.04.2016 16:59:24
- Last modified 12.04.2025 10:46:40
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, whi...
CVE-2016-3630
- EPSS 5.19%
- Published 13.04.2016 16:59:20
- Last modified 12.04.2025 10:46:40
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
CVE-2016-3069
- EPSS 2.83%
- Published 13.04.2016 16:59:17
- Last modified 12.04.2025 10:46:40
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
CVE-2016-3068
- EPSS 5%
- Published 13.04.2016 16:59:16
- Last modified 12.04.2025 10:46:40
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
CVE-2016-2191
- EPSS 2.84%
- Published 13.04.2016 16:59:11
- Last modified 12.04.2025 10:46:40
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.
- EPSS 0.07%
- Published 13.04.2016 15:59:05
- Last modified 12.04.2025 10:46:40
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) ...
CVE-2015-8080
- EPSS 2.73%
- Published 13.04.2016 15:59:04
- Last modified 12.04.2025 10:46:40
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and appl...
CVE-2015-7545
- EPSS 34.73%
- Published 13.04.2016 15:59:01
- Last modified 12.04.2025 10:46:40
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execut...