CVE-2015-8917
- EPSS 6.64%
- Veröffentlicht 20.09.2016 14:15:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
CVE-2015-8916
- EPSS 0.9%
- Veröffentlicht 20.09.2016 14:15:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar...
CVE-2016-6211
- EPSS 1.75%
- Veröffentlicht 09.09.2016 14:05:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.
CVE-2016-7180
- EPSS 0.56%
- Veröffentlicht 09.09.2016 10:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-ipmi-trace.c in the IPMI trace dissector in Wireshark 2.x before 2.0.6 does not properly consider whether a string is constant, which allows remote attackers to cause a denial of service (use-after-free and application crash) v...
CVE-2016-7179
- EPSS 0.68%
- Veröffentlicht 09.09.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
CVE-2016-7178
- EPSS 0.56%
- Veröffentlicht 09.09.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 2.x before 2.0.6 does not ensure that memory is allocated for certain data structures, which allows remote attackers to cause a denial of service (invalid write access and applica...
CVE-2016-7177
- EPSS 0.56%
- Veröffentlicht 09.09.2016 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, which allows remote attackers to cause a denial of service (buffer over-read and application crash) vi...
CVE-2016-7176
- EPSS 0.51%
- Veröffentlicht 09.09.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
epan/dissectors/packet-h225.c in the H.225 dissector in Wireshark 2.x before 2.0.6 calls snprintf with one of its input buffers as the output buffer, which allows remote attackers to cause a denial of service (copy overlap and application crash) via ...
CVE-2016-6318
- EPSS 3.62%
- Veröffentlicht 07.09.2016 19:28:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the FascistGecosUser function in lib/fascist.c in cracklib allows local users to cause a denial of service (application crash) or gain privileges via a long GECOS field, involving longbuffer.
CVE-2016-6316
- EPSS 1.53%
- Veröffentlicht 07.09.2016 19:28:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as ...