CVE-2015-8474
- EPSS 0.37%
- Published 12.04.2016 14:59:05
- Last modified 12.04.2025 10:46:40
Open redirect vulnerability in the valid_back_url function in app/controllers/application_controller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct p...
CVE-2015-8473
- EPSS 0.47%
- Published 12.04.2016 14:59:04
- Last modified 12.04.2025 10:46:40
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other proj...
CVE-2015-8346
- EPSS 0.47%
- Published 12.04.2016 14:59:03
- Last modified 12.04.2025 10:46:40
app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive information about subjects of issues by viewing the time logging form.
CVE-2016-2857
- EPSS 0.06%
- Published 12.04.2016 02:00:07
- Last modified 12.04.2025 10:46:40
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
CVE-2016-1568
- EPSS 0.33%
- Published 12.04.2016 02:00:05
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ)...
CVE-2015-8710
- EPSS 4.71%
- Published 11.04.2016 21:59:15
- Last modified 12.04.2025 10:46:40
The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed H...
- EPSS 25.3%
- Published 11.04.2016 15:59:05
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execut...
- EPSS 1.04%
- Published 11.04.2016 15:59:03
- Last modified 12.04.2025 10:46:40
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
CVE-2012-6700
- EPSS 0.51%
- Published 11.04.2016 15:59:02
- Last modified 12.04.2025 10:46:40
The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of service via a crafted response.
CVE-2012-6699
- EPSS 0.56%
- Published 11.04.2016 15:59:01
- Last modified 12.04.2025 10:46:40
The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted response.