CVE-2016-1899
- EPSS 0.65%
- Veröffentlicht 20.01.2016 16:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype para...
CVE-2015-5295
- EPSS 1.64%
- Veröffentlicht 20.01.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files ...
CVE-2016-1494
- EPSS 5.09%
- Veröffentlicht 13.01.2016 15:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
CVE-2015-8466
- EPSS 0.34%
- Veröffentlicht 13.01.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
CVE-2016-1232
- EPSS 0.71%
- Veröffentlicht 12.01.2016 20:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
CVE-2016-1231
- EPSS 0.74%
- Veröffentlicht 12.01.2016 20:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
CVE-2015-8400
- EPSS 0.56%
- Veröffentlicht 12.01.2016 19:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
CVE-2015-1779
- EPSS 5.57%
- Veröffentlicht 12.01.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
CVE-2015-6566
- EPSS 0.04%
- Veröffentlicht 11.01.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
CVE-2015-5254
- EPSS 77.15%
- Veröffentlicht 08.01.2016 19:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.