CVE-2014-9761
- EPSS 3.82%
- Veröffentlicht 19.04.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) ...
CVE-2016-3960
- EPSS 0.08%
- Veröffentlicht 19.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
CVE-2016-3071
- EPSS 0.97%
- Veröffentlicht 18.04.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
CVE-2015-8106
- EPSS 0.88%
- Veröffentlicht 18.04.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.
CVE-2016-3144
- EPSS 0.22%
- Veröffentlicht 15.04.2016 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
CVE-2016-2146
- EPSS 0.65%
- Veröffentlicht 15.04.2016 14:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount o...
CVE-2016-2145
- EPSS 0.8%
- Veröffentlicht 15.04.2016 14:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST ...
CVE-2015-8540
- EPSS 13.55%
- Veröffentlicht 14.04.2016 14:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impa...
CVE-2016-0787
- EPSS 4.07%
- Veröffentlicht 13.04.2016 17:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes...
CVE-2016-0739
- EPSS 4.31%
- Veröffentlicht 13.04.2016 17:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH ...