CVE-2016-1244
- EPSS 9.94%
- Veröffentlicht 03.10.2016 18:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
CVE-2016-1243
- EPSS 27.59%
- Veröffentlicht 03.10.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.
CVE-2016-5180
- EPSS 19.37%
- Veröffentlicht 03.10.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CVE-2016-7568
- EPSS 1.02%
- Veröffentlicht 28.09.2016 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspe...
CVE-2016-7045
- EPSS 1.93%
- Veröffentlicht 27.09.2016 15:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.
CVE-2016-7044
- EPSS 1.93%
- Veröffentlicht 27.09.2016 15:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.
CVE-2016-6306
- EPSS 11.74%
- Veröffentlicht 26.09.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVE-2016-7142
- EPSS 0.14%
- Veröffentlicht 26.09.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.
CVE-2016-4303
- EPSS 5.73%
- Veröffentlicht 26.09.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based b...
CVE-2016-5172
- EPSS 1.49%
- Veröffentlicht 25.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.