CVE-2016-6306
- EPSS 10.4%
- Veröffentlicht 26.09.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVE-2016-6304
- EPSS 15.83%
- Veröffentlicht 26.09.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
CVE-2016-5172
- EPSS 1.13%
- Veröffentlicht 25.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.
CVE-2016-6303
- EPSS 13.06%
- Veröffentlicht 16.09.2016 05:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...
CVE-2016-2183
- EPSS 54.79%
- Veröffentlicht 01.09.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-3956
- EPSS 0.79%
- Veröffentlicht 02.07.2016 14:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive ...
CVE-2016-2178
- EPSS 0.25%
- Veröffentlicht 20.06.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
CVE-2016-1669
- EPSS 1.63%
- Veröffentlicht 14.05.2016 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer ...
CVE-2016-2107
- EPSS 79.39%
- Veröffentlicht 05.05.2016 01:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against...
CVE-2016-2105
- EPSS 32.64%
- Veröffentlicht 05.05.2016 01:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.