CVE-2015-5345
- EPSS 32.37%
- Published 25.02.2016 01:59:01
- Last modified 12.04.2025 10:46:40
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence o...
CVE-2015-5174
- EPSS 0.93%
- Published 25.02.2016 01:59:00
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.....
CVE-2013-7448
- EPSS 0.55%
- Published 23.02.2016 19:59:00
- Last modified 12.04.2025 10:46:40
Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.
CVE-2016-2037
- EPSS 19.45%
- Published 22.02.2016 15:59:00
- Last modified 12.04.2025 10:46:40
The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
- EPSS 3.21%
- Published 21.02.2016 18:59:01
- Last modified 12.04.2025 10:46:40
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
CVE-2016-1628
- EPSS 0.91%
- Published 21.02.2016 05:59:00
- Last modified 12.04.2025 10:46:40
pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 ...
CVE-2016-2270
- EPSS 0.3%
- Published 19.02.2016 16:59:00
- Last modified 12.04.2025 10:46:40
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
CVE-2015-7547
- EPSS 93.42%
- Published 18.02.2016 21:59:00
- Last modified 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrar...
CVE-2016-0773
- EPSS 6.95%
- Published 17.02.2016 15:59:02
- Last modified 12.04.2025 10:46:40
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a ...
- EPSS 0.97%
- Published 17.02.2016 15:59:01
- Last modified 12.04.2025 10:46:40
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privilege...