CVE-2016-7401
- EPSS 2.95%
- Veröffentlicht 03.10.2016 18:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.
CVE-2016-6352
- EPSS 1.77%
- Veröffentlicht 03.10.2016 18:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.
CVE-2016-1372
- EPSS 0.52%
- Veröffentlicht 03.10.2016 18:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
CVE-2016-1371
- EPSS 0.52%
- Veröffentlicht 03.10.2016 18:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
CVE-2016-5180
- EPSS 20.32%
- Veröffentlicht 03.10.2016 15:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.
CVE-2016-7045
- EPSS 1.92%
- Veröffentlicht 27.09.2016 15:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.
CVE-2016-7044
- EPSS 1.93%
- Veröffentlicht 27.09.2016 15:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.
CVE-2016-6306
- EPSS 8.13%
- Veröffentlicht 26.09.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVE-2016-7162
- EPSS 1.15%
- Veröffentlicht 26.09.2016 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
CVE-2015-8934
- EPSS 1.36%
- Veröffentlicht 20.09.2016 14:15:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.