CVE-2016-2318
- EPSS 0.24%
- Veröffentlicht 03.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath...
CVE-2016-4570
- EPSS 0.81%
- Veröffentlicht 03.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
CVE-2016-4571
- EPSS 0.81%
- Veröffentlicht 03.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mxml_write_node function in mxml-file.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.
CVE-2016-5241
- EPSS 0.35%
- Veröffentlicht 03.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.
CVE-2016-9963
- EPSS 1.68%
- Veröffentlicht 01.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVE-2016-7798
- EPSS 0.6%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.
CVE-2016-9119
- EPSS 0.76%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2016-2518
- EPSS 1.47%
- Veröffentlicht 30.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
CVE-2016-9939
- EPSS 5.92%
- Veröffentlicht 30.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 object. If there is not enough content octets in the ASN.1 object, then t...
CVE-2015-7977
- EPSS 9.71%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.