CVE-2014-9655
- EPSS 1.11%
- Veröffentlicht 13.04.2016 17:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cv...
CVE-2016-3982
- EPSS 2.21%
- Veröffentlicht 13.04.2016 16:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, whi...
CVE-2016-3981
- EPSS 0.95%
- Veröffentlicht 13.04.2016 16:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image ...
CVE-2016-3630
- EPSS 5.19%
- Veröffentlicht 13.04.2016 16:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
CVE-2016-3159
- EPSS 0.04%
- Veröffentlicht 13.04.2016 16:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest ...
CVE-2016-3069
- EPSS 2.83%
- Veröffentlicht 13.04.2016 16:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
CVE-2016-3068
- EPSS 5%
- Veröffentlicht 13.04.2016 16:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
CVE-2016-2533
- EPSS 2.2%
- Veröffentlicht 13.04.2016 16:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.
CVE-2016-2228
- EPSS 0.58%
- Veröffentlicht 13.04.2016 16:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield...
CVE-2016-2191
- EPSS 2.06%
- Veröffentlicht 13.04.2016 16:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.