CVE-2016-1669
- EPSS 4.82%
- Published 14.05.2016 21:59:09
- Last modified 12.04.2025 10:46:40
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer ...
CVE-2016-2107
- EPSS 79.14%
- Published 05.05.2016 01:59:03
- Last modified 12.04.2025 10:46:40
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against...
CVE-2016-2105
- EPSS 50.8%
- Published 05.05.2016 01:59:01
- Last modified 12.04.2025 10:46:40
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
CVE-2016-2216
- EPSS 2.11%
- Published 07.04.2016 21:59:02
- Last modified 12.04.2025 10:46:40
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded U...
CVE-2016-2086
- EPSS 0.45%
- Published 07.04.2016 21:59:01
- Last modified 12.04.2025 10:46:40
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
CVE-2016-0797
- EPSS 30.74%
- Published 03.03.2016 20:59:01
- Last modified 12.04.2025 10:46:40
Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit stri...
CVE-2016-0702
- EPSS 0.46%
- Published 03.03.2016 20:59:00
- Last modified 12.04.2025 10:46:40
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discov...
CVE-2015-8027
- EPSS 1.5%
- Published 02.01.2016 21:59:17
- Last modified 12.04.2025 10:46:40
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined ...
CVE-2015-3194
- EPSS 64.59%
- Published 06.12.2015 20:59:04
- Last modified 12.04.2025 10:46:40
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function p...
CVE-2015-3193
- EPSS 26.94%
- Published 06.12.2015 20:59:02
- Last modified 12.04.2025 10:46:40
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for r...