CVE-2012-6702
- EPSS 0.63%
- Veröffentlicht 16.06.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.
CVE-2016-5338
- EPSS 0.08%
- Veröffentlicht 14.06.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information tran...
CVE-2016-5337
- EPSS 0.05%
- Veröffentlicht 14.06.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
CVE-2016-5238
- EPSS 0.06%
- Veröffentlicht 14.06.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
CVE-2016-4579
- EPSS 1.16%
- Veröffentlicht 13.06.2016 19:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
CVE-2016-4574
- EPSS 0.96%
- Veröffentlicht 13.06.2016 19:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of a...
CVE-2016-4356
- EPSS 0.96%
- Veröffentlicht 13.06.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
CVE-2016-4355
- EPSS 0.83%
- Veröffentlicht 13.06.2016 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4354
- EPSS 1.07%
- Veröffentlicht 13.06.2016 19:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4353
- EPSS 1.08%
- Veröffentlicht 13.06.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.