CVE-2016-5770
- EPSS 10.05%
- Veröffentlicht 07.08.2016 10:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large inte...
CVE-2016-5766
- EPSS 16.23%
- Veröffentlicht 07.08.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based ...
CVE-2016-5116
- EPSS 2.4%
- Veröffentlicht 07.08.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer ...
CVE-2016-3070
- EPSS 0.07%
- Veröffentlicht 06.08.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate.c, which allows local users to cause a denial of service (NULL pointer dereference and system crash)...
CVE-2016-3822
- EPSS 0.35%
- Veröffentlicht 05.08.2016 20:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds ac...
CVE-2016-6186
- EPSS 13.1%
- Veröffentlicht 05.08.2016 15:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in contrib/admin/static/admin/js/admin/RelatedObjectLookups.js in Django before 1.8.14, 1.9.x before 1.9.8, and 1.10.x before 1.10rc1 allows remote attackers to ...
CVE-2016-5403
- EPSS 0.07%
- Veröffentlicht 02.08.2016 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
CVE-2016-6185
- EPSS 0.25%
- Veröffentlicht 02.08.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
CVE-2016-1238
- EPSS 0.33%
- Veröffentlicht 02.08.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpa...
CVE-2016-3992
- EPSS 0.06%
- Veröffentlicht 26.07.2016 17:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.