CVE-2016-0747
- EPSS 33.18%
- Veröffentlicht 15.02.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
CVE-2016-0746
- EPSS 14.01%
- Veröffentlicht 15.02.2016 19:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response relate...
CVE-2016-0742
- EPSS 80.36%
- Veröffentlicht 15.02.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2016-2073
- EPSS 1.32%
- Veröffentlicht 12.02.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
CVE-2016-2330
- EPSS 0.87%
- Veröffentlicht 12.02.2016 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to t...
CVE-2016-2326
- EPSS 0.82%
- Veröffentlicht 12.02.2016 05:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a ...
CVE-2016-0728
- EPSS 43.95%
- Veröffentlicht 08.02.2016 03:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and us...
CVE-2015-8767
- EPSS 0.12%
- Veröffentlicht 08.02.2016 03:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a crafted sctp_accept call.
CVE-2015-8539
- EPSS 0.07%
- Veröffentlicht 08.02.2016 03:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/ke...
CVE-2015-7513
- EPSS 0.06%
- Veröffentlicht 08.02.2016 03:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_v...