CVE-2015-8929
- EPSS 0.27%
- Published 20.09.2016 14:15:16
- Last modified 12.04.2025 10:46:40
Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.
CVE-2015-8928
- EPSS 0.3%
- Published 20.09.2016 14:15:15
- Last modified 12.04.2025 10:46:40
The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
CVE-2015-8926
- EPSS 0.41%
- Published 20.09.2016 14:15:13
- Last modified 12.04.2025 10:46:40
The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
CVE-2015-8925
- EPSS 0.51%
- Published 20.09.2016 14:15:11
- Last modified 12.04.2025 10:46:40
The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.
CVE-2016-5772
- EPSS 15.31%
- Published 07.08.2016 10:59:20
- Last modified 12.04.2025 10:46:40
Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execu...
CVE-2015-8808
- EPSS 0.29%
- Published 13.07.2016 15:59:00
- Last modified 12.04.2025 10:46:40
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.
- EPSS 35.42%
- Published 10.06.2016 15:59:06
- Last modified 12.04.2025 10:46:40
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
CVE-2015-5041
- EPSS 0.89%
- Published 06.06.2016 17:59:00
- Last modified 12.04.2025 10:46:40
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote attackers to obtain sensitive information or inject data by invoking non-public interface methods.
CVE-2016-0718
- EPSS 1.5%
- Published 26.05.2016 16:59:00
- Last modified 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
CVE-2016-0264
- EPSS 9.84%
- Published 24.05.2016 15:59:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows re...