Количество 24 178
Количество 24 178
CVE-2016-7193
Microsoft Office Memory Corruption Vulnerability
CVE-2016-7188
Windows Diagnostics Hub Elevation of Privilege Vulnerability
CVE-2016-7185
Win32k Elevation of Privilege Vulnerability
CVE-2016-7184
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2016-7182
Graphics Component Font Parsing Elevation of Privilege Vulnerability
CVE-2016-7181
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7161
CVE-2016-6664
CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVE-2016-5386
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-4912
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service
CVE-2016-4074
CVE-2016-3959
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
CVE-2016-3709
CVE-2016-3697
CVE-2016-3396
GDI+ Remote Code Execution Vulnerability
CVE-2016-3393
GDI+ Remote Code Execution Vulnerability
CVE-2016-3392
Internet Explorer Security Feature Bypass Vulnerability
CVE-2016-3391
Microsoft Browser Information Disclosure Vulnerability
CVE-2016-3390
Scripting Engine Memory Corruption Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-7193 Microsoft Office Memory Corruption Vulnerability | 58% Средний | почти 10 лет назад | ||
CVE-2016-7188 Windows Diagnostics Hub Elevation of Privilege Vulnerability | 4% Низкий | почти 10 лет назад | ||
CVE-2016-7185 Win32k Elevation of Privilege Vulnerability | 3% Низкий | почти 10 лет назад | ||
CVE-2016-7184 Windows Common Log File System Driver Elevation of Privilege Vulnerability | CVSS3: 6.5 | 7% Низкий | больше 9 лет назад | |
CVE-2016-7182 Graphics Component Font Parsing Elevation of Privilege Vulnerability | 30% Средний | почти 10 лет назад | ||
CVE-2016-7181 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 4.2 | 14% Средний | больше 9 лет назад | |
CVSS3: 9.8 | 6% Низкий | почти 6 лет назад | ||
CVSS3: 7 | 3% Низкий | почти 6 лет назад | ||
CVE-2016-6210 sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided. | CVSS3: 5.9 | 89% Высокий | 11 месяцев назад | |
CVE-2016-5386 The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. | 5% Низкий | 11 месяцев назад | ||
CVE-2016-4912 The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service | CVSS3: 7.5 | 5% Низкий | 10 месяцев назад | |
CVSS3: 7.5 | 5% Низкий | почти 6 лет назад | ||
CVE-2016-3959 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries. | 4% Низкий | 11 месяцев назад | ||
CVSS3: 6.1 | 1% Низкий | почти 4 года назад | ||
CVSS3: 7.8 | 0% Низкий | около 5 лет назад | ||
CVE-2016-3396 GDI+ Remote Code Execution Vulnerability | 24% Средний | почти 10 лет назад | ||
CVE-2016-3393 GDI+ Remote Code Execution Vulnerability | CVSS3: 8.8 | 69% Средний | почти 10 лет назад | |
CVE-2016-3392 Internet Explorer Security Feature Bypass Vulnerability | 10% Низкий | почти 10 лет назад | ||
CVE-2016-3391 Microsoft Browser Information Disclosure Vulnerability | 8% Низкий | почти 10 лет назад | ||
CVE-2016-3390 Scripting Engine Memory Corruption Vulnerability | CVSS3: 7.1 | 17% Средний | почти 10 лет назад |
Уязвимостей на страницу