CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-2178
- EPSS 0.22%
- Veröffentlicht 20.06.2016 01:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
CVE-2016-2177
- EPSS 29.06%
- Veröffentlicht 20.06.2016 01:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveragi...
- EPSS 31.78%
- Veröffentlicht 10.06.2016 15:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
- EPSS 1.55%
- Veröffentlicht 09.06.2016 16:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-5126
- EPSS 0.26%
- Veröffentlicht 01.06.2016 22:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
CVE-2016-4951
- EPSS 0.11%
- Veröffentlicht 23.05.2016 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other...
CVE-2016-4913
- EPSS 0.08%
- Veröffentlicht 23.05.2016 10:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have...
CVE-2016-4805
- EPSS 0.13%
- Veröffentlicht 23.05.2016 10:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a n...
CVE-2016-4581
- EPSS 0.05%
- Veröffentlicht 23.05.2016 10:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series ...