CVE-2012-6698
- EPSS 0.56%
- Veröffentlicht 11.04.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted response.
CVE-2016-2381
- EPSS 18.02%
- Veröffentlicht 08.04.2016 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
CVE-2016-3153
- EPSS 1.46%
- Veröffentlicht 08.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
CVE-2016-2851
- EPSS 23.06%
- Veröffentlicht 07.04.2016 23:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-...
CVE-2016-2098
- EPSS 86.07%
- Veröffentlicht 07.04.2016 23:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
CVE-2016-2511
- EPSS 0.39%
- Veröffentlicht 07.04.2016 21:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.
CVE-2016-2510
- EPSS 37.92%
- Veröffentlicht 07.04.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
CVE-2016-2858
- EPSS 0.12%
- Veröffentlicht 07.04.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
CVE-2015-8837
- EPSS 1.06%
- Veröffentlicht 30.03.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.
CVE-2016-1650
- EPSS 1.14%
- Veröffentlicht 29.03.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The PageCaptureSaveAsMHTMLFunction::ReturnFailure function in browser/extensions/api/page_capture/page_capture_api.cc in Google Chrome before 49.0.2623.108 allows attackers to cause a denial of service or possibly have unspecified other impact by tri...