- EPSS 1.31%
- Published 13.04.2016 14:59:11
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via a service definition, related to executing unzip w...
CVE-2015-8614
- EPSS 1.39%
- Published 11.04.2016 21:59:13
- Last modified 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the (1) conv_jistoeuc, (2) conv_euctojis, and (3) conv_sjistoeuc functions in codeconv.c in Claws Mail before 3.13.1 allow remote attackers to have unspecified impact via a crafted email, involving Japanese ch...
CVE-2016-2381
- EPSS 18.02%
- Published 08.04.2016 15:59:05
- Last modified 12.04.2025 10:46:40
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
CVE-2015-5969
- EPSS 0.13%
- Published 08.04.2016 15:59:01
- Last modified 12.04.2025 10:46:40
The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Lin...
- EPSS 35.46%
- Published 08.04.2016 14:59:02
- Last modified 12.04.2025 10:46:40
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
- EPSS 25.72%
- Published 08.04.2016 14:59:01
- Last modified 12.04.2025 10:46:40
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVE-2016-2851
- EPSS 23.06%
- Published 07.04.2016 23:59:09
- Last modified 12.04.2025 10:46:40
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-...
CVE-2015-2774
- EPSS 0.8%
- Published 07.04.2016 21:59:00
- Last modified 12.04.2025 10:46:40
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).
CVE-2016-3125
- EPSS 1.37%
- Published 05.04.2016 20:59:00
- Last modified 12.04.2025 10:46:40
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecif...
CVE-2016-3679
- EPSS 0.85%
- Published 29.03.2016 10:59:05
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.