CVE-2016-3717
- EPSS 40.02%
- Veröffentlicht 05.05.2016 18:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
CVE-2016-3716
- EPSS 29.87%
- Veröffentlicht 05.05.2016 18:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
CVE-2016-3715
- EPSS 89.25%
- Veröffentlicht 05.05.2016 18:59:04
- Zuletzt bearbeitet 22.04.2026 14:35:10
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
- EPSS 93.86%
- Veröffentlicht 05.05.2016 18:59:03
- Zuletzt bearbeitet 21.04.2026 19:14:46
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "I...
CVE-2016-2107
- EPSS 79.96%
- Veröffentlicht 05.05.2016 01:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against...
CVE-2016-2105
- EPSS 42.47%
- Veröffentlicht 05.05.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
CVE-2016-3951
- EPSS 0.06%
- Veröffentlicht 02.05.2016 10:59:41
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invali...
CVE-2016-3689
- EPSS 0.09%
- Veröffentlicht 02.05.2016 10:59:40
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
CVE-2016-3140
- EPSS 0.16%
- Veröffentlicht 02.05.2016 10:59:39
- Zuletzt bearbeitet 06.05.2026 22:30:45
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB...
CVE-2016-3138
- EPSS 0.02%
- Veröffentlicht 02.05.2016 10:59:37
- Zuletzt bearbeitet 06.05.2026 22:30:45
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data e...