CVE-2016-3961
- EPSS 0.13%
- Veröffentlicht 15.04.2016 14:59:14
- Zuletzt bearbeitet 06.05.2026 22:30:45
Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.
CVE-2015-5247
- EPSS 0.39%
- Veröffentlicht 14.04.2016 15:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS po...
CVE-2011-4600
- EPSS 0.35%
- Veröffentlicht 14.04.2016 15:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restriction...
CVE-2015-8560
- EPSS 9.26%
- Veröffentlicht 14.04.2016 14:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different...
CVE-2016-0739
- EPSS 3.66%
- Veröffentlicht 13.04.2016 17:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH ...
CVE-2015-8806
- EPSS 8.57%
- Veröffentlicht 13.04.2016 17:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.
CVE-2015-3146
- EPSS 2.41%
- Veröffentlicht 13.04.2016 17:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted S...
CVE-2016-3982
- EPSS 2.51%
- Veröffentlicht 13.04.2016 16:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, whi...
CVE-2016-3981
- EPSS 0.95%
- Veröffentlicht 13.04.2016 16:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image ...
CVE-2016-2191
- EPSS 1.74%
- Veröffentlicht 13.04.2016 16:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.