CVE-2016-9453
- EPSS 0.42%
- Veröffentlicht 27.01.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.
CVE-2016-10159
- EPSS 8.08%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PH...
CVE-2016-10160
- EPSS 4.7%
- Veröffentlicht 24.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archiv...
CVE-2016-9401
- EPSS 0.06%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 06.08.2025 22:15:28
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2015-8971
- EPSS 0.64%
- Veröffentlicht 23.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063.
CVE-2016-7799
- EPSS 1.3%
- Veröffentlicht 18.01.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CVE-2016-7906
- EPSS 0.47%
- Veröffentlicht 18.01.2017 17:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
CVE-2016-9811
- EPSS 0.49%
- Veröffentlicht 13.01.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVE-2016-2090
- EPSS 1.71%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-9131
- EPSS 72.83%
- Veröffentlicht 12.01.2017 06:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.