CVE-2016-2342
- EPSS 20.44%
- Veröffentlicht 17.03.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration is used, relies on a Labeled-VPN SAFI routes-data length field during a data copy, which allows remo...
CVE-2016-2856
- EPSS 0.68%
- Veröffentlicht 14.03.2016 01:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubuntu4.2 on Ubuntu 15.10 and befo...
CVE-2016-1645
- EPSS 2.19%
- Veröffentlicht 13.03.2016 22:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or...
CVE-2015-7560
- EPSS 4%
- Veröffentlicht 13.03.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then u...
CVE-2016-1286
- EPSS 53.59%
- Veröffentlicht 09.03.2016 23:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
CVE-2016-1285
- EPSS 68.97%
- Veröffentlicht 09.03.2016 23:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed...
CVE-2016-2774
- EPSS 65.58%
- Veröffentlicht 09.03.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establis...
CVE-2016-0797
- EPSS 34.19%
- Veröffentlicht 03.03.2016 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit stri...
CVE-2016-0702
- EPSS 0.36%
- Veröffentlicht 03.03.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discov...
- EPSS 24.28%
- Veröffentlicht 03.03.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other imp...