CVE-2016-1652
- EPSS 0.41%
- Veröffentlicht 18.04.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the Extensions subsystem in Google Chrome before 50.0.2661.75 allows remote attackers to inject arbitrary web script o...
CVE-2016-1651
- EPSS 1.39%
- Veröffentlicht 18.04.2016 10:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory...
CVE-2015-8560
- EPSS 9.26%
- Veröffentlicht 14.04.2016 14:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different...
CVE-2015-8540
- EPSS 13.55%
- Veröffentlicht 14.04.2016 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...
- EPSS 23.93%
- Veröffentlicht 14.04.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in util.c in mod_dav_svn in Apache Subversion 1.7.x, 1.8.x before 1.8.15, and 1.9.x before 1.9.3 allows remote authenticated users to cause a denial of service (subversion server crash or memory consumption) and possibly execute arbi...
CVE-2016-0787
- EPSS 3.15%
- Veröffentlicht 13.04.2016 17:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes...
CVE-2016-0739
- EPSS 3.66%
- Veröffentlicht 13.04.2016 17:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH ...
CVE-2015-8806
- EPSS 8.57%
- Veröffentlicht 13.04.2016 17:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
CVE-2015-8784
- EPSS 1.52%
- Veröffentlicht 13.04.2016 17:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2015-8683
- EPSS 0.21%
- Veröffentlicht 13.04.2016 17:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a packed TIFF image.