CVE-2016-3674
- EPSS 4.22%
- Veröffentlicht 17.05.2016 14:08:03
- Zuletzt bearbeitet 23.05.2025 17:54:18
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...
CVE-2016-3627
- EPSS 0.09%
- Veröffentlicht 17.05.2016 14:08:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML doc...
CVE-2015-4643
- EPSS 8.66%
- Veröffentlicht 16.05.2016 10:59:15
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer ov...
CVE-2015-3152
- EPSS 51.67%
- Veröffentlicht 16.05.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade at...
CVE-2016-1670
- EPSS 0.68%
- Veröffentlicht 14.05.2016 21:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a...
CVE-2016-1669
- EPSS 1.63%
- Veröffentlicht 14.05.2016 21:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer ...
CVE-2016-1668
- EPSS 1.2%
- Veröffentlicht 14.05.2016 21:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy ...
CVE-2016-1667
- EPSS 0.62%
- Veröffentlicht 14.05.2016 21:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote at...
CVE-2016-4024
- EPSS 9.63%
- Veröffentlicht 13.05.2016 16:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.
CVE-2016-3994
- EPSS 0.99%
- Veröffentlicht 13.05.2016 16:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.