CVE-2016-2216
- EPSS 1.42%
- Veröffentlicht 07.04.2016 21:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded U...
CVE-2016-0729
- EPSS 23.02%
- Veröffentlicht 07.04.2016 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corrupti...
CVE-2016-2086
- EPSS 0.45%
- Veröffentlicht 07.04.2016 21:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
CVE-2016-3125
- EPSS 1.37%
- Veröffentlicht 05.04.2016 20:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecif...
CVE-2015-8837
- EPSS 1.11%
- Veröffentlicht 30.03.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.
CVE-2015-8836
- EPSS 0.49%
- Veröffentlicht 30.03.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leadi...
CVE-2016-1286
- EPSS 60.01%
- Veröffentlicht 09.03.2016 23:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
CVE-2016-1285
- EPSS 66.46%
- Veröffentlicht 09.03.2016 23:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed...
CVE-2016-2316
- EPSS 1.09%
- Veröffentlicht 22.02.2016 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set to a value greater than 1245,...
CVE-2016-0725
- EPSS 0.6%
- Veröffentlicht 22.02.2016 05:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or H...