CVE-2016-2147
- EPSS 8.29%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RFC1035-encoded domain name, which triggers an out-of-bounds heap write.
CVE-2016-2148
- EPSS 15.84%
- Veröffentlicht 09.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.
CVE-2016-10165
- EPSS 0.87%
- Veröffentlicht 03.02.2017 19:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
CVE-2016-9963
- EPSS 1.88%
- Veröffentlicht 01.02.2017 15:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVE-2016-9119
- EPSS 0.81%
- Veröffentlicht 30.01.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-7973
- EPSS 8.6%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2015-7977
- EPSS 16.35%
- Veröffentlicht 30.01.2017 21:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2017-3313
- EPSS 0.05%
- Veröffentlicht 27.01.2017 22:59:04
- Zuletzt bearbeitet 13.05.2026 00:24:29
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Difficult to exploit vulnerability allows low privileg...
CVE-2016-5824
- EPSS 0.29%
- Veröffentlicht 27.01.2017 22:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVE-2016-2090
- EPSS 1.94%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.