CVE-2016-2182
- EPSS 36.38%
- Published 16.09.2016 05:59:02
- Last modified 12.04.2025 10:46:40
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified ot...
CVE-2016-2181
- EPSS 23.03%
- Published 16.09.2016 05:59:01
- Last modified 12.04.2025 10:46:40
The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops...
CVE-2016-2179
- EPSS 16.96%
- Published 16.09.2016 05:59:00
- Last modified 12.04.2025 10:46:40
The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many...
CVE-2016-5404
- EPSS 0.34%
- Published 07.09.2016 20:59:01
- Last modified 12.04.2025 10:46:40
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
CVE-2016-5408
- EPSS 5.37%
- Published 10.08.2016 14:59:02
- Last modified 12.04.2025 10:46:40
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerabil...
CVE-2016-6198
- EPSS 0.04%
- Published 06.08.2016 20:59:13
- Last modified 12.04.2025 10:46:40
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related t...
CVE-2016-6197
- EPSS 0.04%
- Published 06.08.2016 20:59:12
- Last modified 12.04.2025 10:46:40
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of serv...
CVE-2016-5265
- EPSS 0.26%
- Published 05.08.2016 01:59:21
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML docu...
CVE-2016-5264
- EPSS 1.01%
- Published 05.08.2016 01:59:20
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru...
CVE-2016-5263
- EPSS 0.68%
- Published 05.08.2016 01:59:19
- Last modified 12.04.2025 10:46:40
The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confu...