Количество 18 763
Количество 18 763
CVE-2016-7203
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7202
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7201
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7200
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7199
Microsoft Browser Information Disclosure Vulnerability
CVE-2016-7198
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7196
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7195
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7193
Microsoft Office Memory Corruption Vulnerability
CVE-2016-7188
Windows Diagnostics Hub Elevation of Privilege Vulnerability
CVE-2016-7185
Win32k Elevation of Privilege Vulnerability
CVE-2016-7184
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2016-7182
Graphics Component Font Parsing Elevation of Privilege Vulnerability
CVE-2016-7181
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7161
CVE-2016-6664
CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVE-2016-5386
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-4912
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service
CVE-2016-4074
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-7203 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 78% Высокий | около 9 лет назад | |
CVE-2016-7202 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 80% Высокий | около 9 лет назад | |
CVE-2016-7201 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 90% Критический | около 9 лет назад | |
CVE-2016-7200 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 89% Высокий | около 9 лет назад | |
CVE-2016-7199 Microsoft Browser Information Disclosure Vulnerability | CVSS3: 4.3 | 17% Средний | около 9 лет назад | |
CVE-2016-7198 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 4.2 | 31% Средний | около 9 лет назад | |
CVE-2016-7196 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 6 | 31% Средний | около 9 лет назад | |
CVE-2016-7195 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 6 | 20% Средний | около 9 лет назад | |
CVE-2016-7193 Microsoft Office Memory Corruption Vulnerability | 71% Высокий | больше 9 лет назад | ||
CVE-2016-7188 Windows Diagnostics Hub Elevation of Privilege Vulnerability | 3% Низкий | больше 9 лет назад | ||
CVE-2016-7185 Win32k Elevation of Privilege Vulnerability | 2% Низкий | больше 9 лет назад | ||
CVE-2016-7184 Windows Common Log File System Driver Elevation of Privilege Vulnerability | CVSS3: 6.5 | 5% Низкий | около 9 лет назад | |
CVE-2016-7182 Graphics Component Font Parsing Elevation of Privilege Vulnerability | 34% Средний | больше 9 лет назад | ||
CVE-2016-7181 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 4.2 | 27% Средний | около 9 лет назад | |
CVSS3: 9.8 | 20% Средний | больше 5 лет назад | ||
CVSS3: 7 | 47% Средний | больше 5 лет назад | ||
CVE-2016-6210 sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided. | CVSS3: 5.9 | 92% Критический | 5 месяцев назад | |
CVE-2016-5386 The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. | 82% Высокий | 5 месяцев назад | ||
CVE-2016-4912 The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVSS3: 7.5 | 1% Низкий | больше 5 лет назад |
Уязвимостей на страницу