CVE-2016-10165
- EPSS 0.51%
- Veröffentlicht 03.02.2017 19:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
CVE-2016-9963
- EPSS 1.68%
- Veröffentlicht 01.02.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVE-2016-9119
- EPSS 0.81%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-7973
- EPSS 8.6%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2015-7977
- EPSS 18.91%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2017-3313
- EPSS 0.05%
- Veröffentlicht 27.01.2017 22:59:04
- Zuletzt bearbeitet 20.04.2025 01:37:25
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileg...
CVE-2016-5824
- EPSS 0.44%
- Veröffentlicht 27.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVE-2016-2090
- EPSS 1.71%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-7426
- EPSS 11.68%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses wit...
CVE-2016-2377
- EPSS 3.31%
- Veröffentlicht 06.01.2017 21:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-lengt...