CVE-2016-5338
- EPSS 0.08%
- Veröffentlicht 14.06.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information tran...
CVE-2016-5337
- EPSS 0.05%
- Veröffentlicht 14.06.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
CVE-2016-5238
- EPSS 0.06%
- Veröffentlicht 14.06.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
CVE-2016-4579
- EPSS 1.16%
- Veröffentlicht 13.06.2016 19:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
CVE-2016-4574
- EPSS 0.96%
- Veröffentlicht 13.06.2016 19:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of a...
CVE-2016-4356
- EPSS 0.96%
- Veröffentlicht 13.06.2016 19:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
CVE-2016-4355
- EPSS 0.83%
- Veröffentlicht 13.06.2016 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4354
- EPSS 0.79%
- Veröffentlicht 13.06.2016 19:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4353
- EPSS 0.8%
- Veröffentlicht 13.06.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
CVE-2016-3698
- EPSS 2.06%
- Veröffentlicht 13.06.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity d...