CVE-2016-4809
- EPSS 2.54%
- Veröffentlicht 21.09.2016 14:25:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
CVE-2015-8922
- EPSS 0.39%
- Veröffentlicht 20.09.2016 14:15:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
CVE-2016-6302
- EPSS 10.38%
- Veröffentlicht 16.09.2016 05:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.
CVE-2016-2182
- EPSS 29.22%
- Veröffentlicht 16.09.2016 05:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified ot...
CVE-2016-2181
- EPSS 24.27%
- Veröffentlicht 16.09.2016 05:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops...
CVE-2016-2179
- EPSS 18.31%
- Veröffentlicht 16.09.2016 05:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many...
CVE-2016-5404
- EPSS 0.47%
- Veröffentlicht 07.09.2016 20:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
CVE-2016-5408
- EPSS 5.37%
- Veröffentlicht 10.08.2016 14:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerabil...
CVE-2016-6198
- EPSS 0.04%
- Veröffentlicht 06.08.2016 20:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related t...
CVE-2016-6197
- EPSS 0.06%
- Veröffentlicht 06.08.2016 20:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of serv...