CVE-2016-2038
- EPSS 1.2%
- Veröffentlicht 20.02.2016 01:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.
CVE-2016-2270
- EPSS 0.3%
- Veröffentlicht 19.02.2016 16:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
CVE-2016-0753
- EPSS 2.33%
- Veröffentlicht 16.02.2016 02:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted para...
CVE-2016-1526
- EPSS 0.76%
- Veröffentlicht 13.02.2016 02:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive inform...
CVE-2016-1523
- EPSS 1.34%
- Veröffentlicht 13.02.2016 02:59:08
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (mis...
CVE-2016-1522
- EPSS 2.42%
- Veröffentlicht 13.02.2016 02:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based...
CVE-2016-1521
- EPSS 0.85%
- Veröffentlicht 13.02.2016 02:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary ...
CVE-2015-7513
- EPSS 0.09%
- Veröffentlicht 08.02.2016 03:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_v...
CVE-2016-1926
- EPSS 0.72%
- Veröffentlicht 26.01.2016 19:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
CVE-2016-1572
- EPSS 0.05%
- Veröffentlicht 22.01.2016 15:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.