CVE-2016-3674
- EPSS 4.22%
- Veröffentlicht 17.05.2016 14:08:03
- Zuletzt bearbeitet 23.05.2025 17:54:18
Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbi...
CVE-2015-3152
- EPSS 51.67%
- Veröffentlicht 16.05.2016 10:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade at...
CVE-2016-2850
- EPSS 0.43%
- Veröffentlicht 13.05.2016 14:59:11
- Zuletzt bearbeitet 06.05.2026 22:30:45
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
CVE-2016-2849
- EPSS 0.58%
- Veröffentlicht 13.05.2016 14:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
CVE-2015-7827
- EPSS 0.44%
- Veröffentlicht 13.05.2016 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
CVE-2015-8868
- EPSS 1.09%
- Veröffentlicht 06.05.2016 17:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mo...
CVE-2016-4008
- EPSS 4.29%
- Veröffentlicht 05.05.2016 18:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
CVE-2016-4002
- EPSS 7.87%
- Veröffentlicht 26.04.2016 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitra...
CVE-2016-3074
- EPSS 60.49%
- Veröffentlicht 26.04.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflo...
CVE-2015-8779
- EPSS 3.58%
- Veröffentlicht 19.04.2016 21:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.