CVE-2015-3146
- EPSS 2.41%
- Veröffentlicht 13.04.2016 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted S...
CVE-2015-1547
- EPSS 4.45%
- Veröffentlicht 13.04.2016 17:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff5.tif.
CVE-2014-9655
- EPSS 1.11%
- Veröffentlicht 13.04.2016 17:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIFF image, as demonstrated by libtiff-cv...
CVE-2016-3982
- EPSS 2.51%
- Veröffentlicht 13.04.2016 16:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, whi...
CVE-2016-3981
- EPSS 0.95%
- Veröffentlicht 13.04.2016 16:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image ...
CVE-2016-3630
- EPSS 5.19%
- Veröffentlicht 13.04.2016 16:59:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
CVE-2016-3159
- EPSS 0.04%
- Veröffentlicht 13.04.2016 16:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest ...
CVE-2016-3069
- EPSS 2.83%
- Veröffentlicht 13.04.2016 16:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
CVE-2016-3068
- EPSS 5%
- Veröffentlicht 13.04.2016 16:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
CVE-2016-2533
- EPSS 2.21%
- Veröffentlicht 13.04.2016 16:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.