CVE-2016-7143
- EPSS 1.01%
- Veröffentlicht 21.09.2016 14:25:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.
CVE-2016-6801
- EPSS 0.36%
- Veröffentlicht 21.09.2016 14:25:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 ...
CVE-2016-6354
- EPSS 37.72%
- Veröffentlicht 21.09.2016 14:25:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
CVE-2015-8871
- EPSS 1.36%
- Veröffentlicht 21.09.2016 14:25:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact via unknown vectors.
- EPSS 89.58%
- Veröffentlicht 20.09.2016 18:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow loc...
CVE-2015-8931
- EPSS 0.27%
- Veröffentlicht 20.09.2016 14:15:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefin...
CVE-2015-8932
- EPSS 0.56%
- Veröffentlicht 20.09.2016 14:15:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.
CVE-2015-8917
- EPSS 5.66%
- Veröffentlicht 20.09.2016 14:15:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
CVE-2015-8916
- EPSS 0.97%
- Veröffentlicht 20.09.2016 14:15:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar...
CVE-2016-6211
- EPSS 1.13%
- Veröffentlicht 09.09.2016 14:05:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that triggers a rebuild of the user profile form.