CVE-2016-4447
- EPSS 2.06%
- Veröffentlicht 09.06.2016 16:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
CVE-2016-2150
- EPSS 0.07%
- Veröffentlicht 09.06.2016 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
- EPSS 15.98%
- Veröffentlicht 09.06.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
CVE-2016-5108
- EPSS 20.82%
- Veröffentlicht 08.06.2016 15:00:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.
CVE-2016-4450
- EPSS 4.02%
- Veröffentlicht 07.06.2016 14:06:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary...
CVE-2016-2335
- EPSS 2.05%
- Veröffentlicht 07.06.2016 14:06:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation D...
CVE-2015-7695
- EPSS 2.25%
- Veröffentlicht 07.06.2016 14:06:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.
CVE-2015-5723
- EPSS 0.03%
- Veröffentlicht 07.06.2016 14:06:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permiss...
CVE-2015-5261
- EPSS 0.09%
- Veröffentlicht 07.06.2016 14:06:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
CVE-2015-5260
- EPSS 0.24%
- Veröffentlicht 07.06.2016 14:06:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter...