CVE-2016-2116
- EPSS 7.34%
- Veröffentlicht 13.04.2016 14:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.
CVE-2016-1577
- EPSS 7.73%
- Veröffentlicht 13.04.2016 14:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, ...
CVE-2014-9766
- EPSS 14.14%
- Veröffentlicht 13.04.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.
CVE-2016-2118
- EPSS 77.14%
- Veröffentlicht 12.04.2016 23:59:37
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersona...
CVE-2016-3157
- EPSS 0.36%
- Veröffentlicht 12.04.2016 16:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause a denial of service (guest OS crash), or obtain se...
CVE-2016-2857
- EPSS 0.06%
- Veröffentlicht 12.04.2016 02:00:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
CVE-2016-2381
- EPSS 19.47%
- Veröffentlicht 08.04.2016 15:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
CVE-2016-2510
- EPSS 38.91%
- Veröffentlicht 07.04.2016 20:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.
CVE-2016-2858
- EPSS 0.12%
- Veröffentlicht 07.04.2016 19:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbitrary stack based allocation and memory corruption.
CVE-2016-3947
- EPSS 78.81%
- Veröffentlicht 07.04.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sen...