CVE-2015-4643
- EPSS 8.66%
- Veröffentlicht 16.05.2016 10:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ov...
CVE-2015-3152
- EPSS 51.67%
- Veröffentlicht 16.05.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade at...
CVE-2016-1670
- EPSS 0.68%
- Veröffentlicht 14.05.2016 21:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a...
CVE-2016-1669
- EPSS 1.63%
- Veröffentlicht 14.05.2016 21:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer ...
CVE-2016-1668
- EPSS 1.2%
- Veröffentlicht 14.05.2016 21:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy ...
CVE-2016-1667
- EPSS 0.62%
- Veröffentlicht 14.05.2016 21:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote at...
CVE-2016-4024
- EPSS 9.63%
- Veröffentlicht 13.05.2016 16:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
CVE-2016-3994
- EPSS 0.99%
- Veröffentlicht 13.05.2016 16:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.
CVE-2016-2860
- EPSS 0.25%
- Veröffentlicht 13.05.2016 16:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the ...
CVE-2016-3993
- EPSS 1.1%
- Veröffentlicht 13.05.2016 16:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.