- EPSS 35.42%
- Veröffentlicht 10.06.2016 15:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
- EPSS 1.2%
- Veröffentlicht 09.06.2016 16:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-5126
- EPSS 0.2%
- Veröffentlicht 01.06.2016 22:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
CVE-2016-4951
- EPSS 0.14%
- Veröffentlicht 23.05.2016 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other...
CVE-2016-4913
- EPSS 0.1%
- Veröffentlicht 23.05.2016 10:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have...
CVE-2016-4805
- EPSS 0.09%
- Veröffentlicht 23.05.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a n...
CVE-2016-4581
- EPSS 0.04%
- Veröffentlicht 23.05.2016 10:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series ...
CVE-2015-4643
- EPSS 10.69%
- Veröffentlicht 16.05.2016 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ov...
CVE-2016-3710
- EPSS 0.09%
- Veröffentlicht 11.05.2016 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Port...
CVE-2016-4556
- EPSS 56.86%
- Veröffentlicht 10.05.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.