CVE-2016-4953
- EPSS 12.64%
- Published 05.07.2016 01:59:00
- Last modified 12.04.2025 10:46:40
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.
CVE-2016-0264
- EPSS 9.84%
- Published 24.05.2016 15:59:00
- Last modified 12.04.2025 10:46:40
Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows re...
CVE-2016-3718
- EPSS 79.25%
- Published 05.05.2016 18:59:08
- Last modified 12.04.2025 10:46:40
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CVE-2016-3715
- EPSS 79.8%
- Published 05.05.2016 18:59:04
- Last modified 12.04.2025 10:46:40
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- EPSS 93.75%
- Published 21.04.2016 11:00:21
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
- EPSS 35.46%
- Published 08.04.2016 14:59:02
- Last modified 12.04.2025 10:46:40
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
- EPSS 25.72%
- Published 08.04.2016 14:59:01
- Last modified 12.04.2025 10:46:40
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
CVE-2016-1286
- EPSS 68.03%
- Published 09.03.2016 23:59:03
- Last modified 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
CVE-2016-1285
- EPSS 67.84%
- Published 09.03.2016 23:59:02
- Last modified 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed...