CVE-2016-5325
- EPSS 0.33%
- Veröffentlicht 10.10.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s...
CVE-2016-5180
- EPSS 19.37%
- Veröffentlicht 03.10.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CVE-2016-7052
- EPSS 13.86%
- Veröffentlicht 26.09.2016 19:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
CVE-2016-6306
- EPSS 9%
- Veröffentlicht 26.09.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVE-2016-6304
- EPSS 20.28%
- Veröffentlicht 26.09.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
CVE-2016-5172
- EPSS 1.49%
- Veröffentlicht 25.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
CVE-2016-6303
- EPSS 32.88%
- Veröffentlicht 16.09.2016 05:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...
CVE-2016-2183
- EPSS 40.02%
- Veröffentlicht 01.09.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-3956
- EPSS 2.39%
- Veröffentlicht 02.07.2016 14:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive ...
CVE-2016-2178
- EPSS 0.33%
- Veröffentlicht 20.06.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.