CVE-2015-8919
- EPSS 7.55%
- Veröffentlicht 20.09.2016 14:15:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.
CVE-2015-8917
- EPSS 6.64%
- Veröffentlicht 20.09.2016 14:15:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
CVE-2015-8916
- EPSS 1.16%
- Veröffentlicht 20.09.2016 14:15:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar...
CVE-2016-6262
- EPSS 6.24%
- Veröffentlicht 07.09.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
CVE-2016-6261
- EPSS 4.35%
- Veröffentlicht 07.09.2016 20:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
CVE-2015-8948
- EPSS 5.44%
- Veröffentlicht 07.09.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
CVE-2016-6855
- EPSS 4.04%
- Veröffentlicht 07.09.2016 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invali...
CVE-2016-6351
- EPSS 0.17%
- Veröffentlicht 07.09.2016 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execut...
- EPSS 0.06%
- Veröffentlicht 02.09.2016 14:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.
- EPSS 0.06%
- Veröffentlicht 02.09.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors in...