CVE-2015-8875
- EPSS 1.14%
- Veröffentlicht 01.06.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash...
CVE-2016-2175
- EPSS 2.17%
- Veröffentlicht 01.06.2016 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.
CVE-2016-0718
- EPSS 1.5%
- Veröffentlicht 26.05.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
CVE-2016-4020
- EPSS 0.06%
- Veröffentlicht 25.05.2016 15:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
- EPSS 0.09%
- Veröffentlicht 23.05.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CV...
CVE-2016-4001
- EPSS 9.37%
- Veröffentlicht 23.05.2016 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of service (QEMU crash) via a large pac...
CVE-2015-8558
- EPSS 0.05%
- Veröffentlicht 23.05.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular isochronous transfer descriptor (iTD) list.
CVE-2016-4578
- EPSS 0.2%
- Veröffentlicht 23.05.2016 10:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_t...
CVE-2016-4565
- EPSS 0.18%
- Veröffentlicht 23.05.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI int...
CVE-2016-4544
- EPSS 3.94%
- Veröffentlicht 22.05.2016 01:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly h...