CVE-2016-1941
- EPSS 0.25%
- Published 31.01.2016 18:59:07
- Last modified 12.04.2025 10:46:40
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a doub...
CVE-2015-8472
- EPSS 3.2%
- Published 21.01.2016 15:59:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or ...
CVE-2016-0778
- EPSS 2.13%
- Published 14.01.2016 22:59:02
- Last modified 12.04.2025 10:46:40
The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy and forward options are enabled, do not properly maintain connection file descriptors, which allows r...
CVE-2016-0777
- EPSS 67.2%
- Published 14.01.2016 22:59:01
- Last modified 12.04.2025 10:46:40
The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading...
- EPSS 2.19%
- Published 12.01.2016 19:59:13
- Last modified 12.04.2025 10:46:40
The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
CVE-2015-7024
- EPSS 0.06%
- Published 11.01.2016 11:59:01
- Last modified 12.04.2025 10:46:40
Untrusted search path vulnerability in Apple OS X before 10.11.1 allows local users to bypass intended Gatekeeper restrictions and gain privileges via a Trojan horse program that is loaded from an unexpected directory by an application that has a val...
CVE-2015-6980
- EPSS 0.04%
- Published 11.01.2016 11:59:00
- Last modified 12.04.2025 10:46:40
Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.
CVE-2015-7116
- EPSS 0.83%
- Published 10.01.2016 03:59:01
- Last modified 12.04.2025 10:46:40
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-711...
CVE-2015-7115
- EPSS 0.83%
- Published 10.01.2016 03:59:00
- Last modified 12.04.2025 10:46:40
libxml2 in Apple iOS before 9.2, OS X before 10.11.2, and tvOS before 9.1 allows remote attackers to obtain sensitive information or cause a denial of service (memory corruption) via a crafted XML document, a different vulnerability than CVE-2015-711...
CVE-2015-8242
- EPSS 1.66%
- Published 15.12.2015 21:59:07
- Last modified 12.04.2025 10:46:40
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive informati...