CVE-2015-8921
- EPSS 4.25%
- Veröffentlicht 20.09.2016 14:15:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
CVE-2015-8920
- EPSS 0.56%
- Veröffentlicht 20.09.2016 14:15:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
CVE-2015-8919
- EPSS 6.45%
- Veröffentlicht 20.09.2016 14:15:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.
CVE-2015-8917
- EPSS 5.66%
- Veröffentlicht 20.09.2016 14:15:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.
CVE-2015-8916
- EPSS 0.97%
- Veröffentlicht 20.09.2016 14:15:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar...
CVE-2016-6262
- EPSS 3.21%
- Veröffentlicht 07.09.2016 20:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
CVE-2016-6261
- EPSS 2.27%
- Veröffentlicht 07.09.2016 20:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
CVE-2015-8948
- EPSS 2.78%
- Veröffentlicht 07.09.2016 20:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
CVE-2016-6855
- EPSS 3.42%
- Veröffentlicht 07.09.2016 18:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invali...
CVE-2016-6351
- EPSS 0.23%
- Veröffentlicht 07.09.2016 18:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execut...