CVE-2016-4555
- EPSS 66.07%
- Veröffentlicht 10.05.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
CVE-2016-4554
- EPSS 73.39%
- Veröffentlicht 10.05.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
CVE-2016-4553
- EPSS 82.84%
- Veröffentlicht 10.05.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
CVE-2016-3718
- EPSS 79.25%
- Veröffentlicht 05.05.2016 18:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
CVE-2016-3715
- EPSS 79.8%
- Veröffentlicht 05.05.2016 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
CVE-2016-2143
- EPSS 0.17%
- Veröffentlicht 27.04.2016 17:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted appli...
CVE-2016-4054
- EPSS 77%
- Veröffentlicht 25.04.2016 14:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVE-2016-4053
- EPSS 9.51%
- Veröffentlicht 25.04.2016 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
CVE-2016-4051
- EPSS 3.67%
- Veröffentlicht 25.04.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
- EPSS 93.75%
- Veröffentlicht 21.04.2016 11:00:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.