Количество 26 087
Количество 26 087
CVE-2016-7201
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7200
Scripting Engine Memory Corruption Vulnerability
CVE-2016-7199
Microsoft Browser Information Disclosure Vulnerability
CVE-2016-7198
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7196
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7195
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7193
Microsoft Office Memory Corruption Vulnerability
CVE-2016-7188
Windows Diagnostics Hub Elevation of Privilege Vulnerability
CVE-2016-7185
Win32k Elevation of Privilege Vulnerability
CVE-2016-7184
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2016-7182
Graphics Component Font Parsing Elevation of Privilege Vulnerability
CVE-2016-7181
Microsoft Browser Memory Corruption Vulnerability
CVE-2016-7161
CVE-2016-6664
CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
CVE-2016-5386
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVE-2016-4912
The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service
CVE-2016-4074
CVE-2016-3959
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
CVE-2016-3709
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-7201 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 80% Высокий | почти 10 лет назад | |
CVE-2016-7200 Scripting Engine Memory Corruption Vulnerability | CVSS3: 4.2 | 82% Высокий | почти 10 лет назад | |
CVE-2016-7199 Microsoft Browser Information Disclosure Vulnerability | CVSS3: 4.3 | 13% Средний | почти 10 лет назад | |
CVE-2016-7198 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 4.2 | 14% Средний | почти 10 лет назад | |
CVE-2016-7196 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 6 | 14% Средний | почти 10 лет назад | |
CVE-2016-7195 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 6 | 17% Средний | почти 10 лет назад | |
CVE-2016-7193 Microsoft Office Memory Corruption Vulnerability | 58% Средний | почти 10 лет назад | ||
CVE-2016-7188 Windows Diagnostics Hub Elevation of Privilege Vulnerability | 4% Низкий | почти 10 лет назад | ||
CVE-2016-7185 Win32k Elevation of Privilege Vulnerability | 3% Низкий | почти 10 лет назад | ||
CVE-2016-7184 Windows Common Log File System Driver Elevation of Privilege Vulnerability | CVSS3: 6.5 | 7% Низкий | почти 10 лет назад | |
CVE-2016-7182 Graphics Component Font Parsing Elevation of Privilege Vulnerability | 30% Средний | почти 10 лет назад | ||
CVE-2016-7181 Microsoft Browser Memory Corruption Vulnerability | CVSS3: 4.2 | 14% Средний | больше 9 лет назад | |
CVSS3: 9.8 | 6% Низкий | почти 6 лет назад | ||
CVSS3: 7 | 3% Низкий | почти 6 лет назад | ||
CVE-2016-6210 sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided. | CVSS3: 5.9 | 89% Высокий | 11 месяцев назад | |
CVE-2016-5386 The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. | 5% Низкий | 11 месяцев назад | ||
CVE-2016-4912 The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service | CVSS3: 7.5 | 5% Низкий | 11 месяцев назад | |
CVSS3: 7.5 | 5% Низкий | почти 6 лет назад | ||
CVE-2016-3959 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries. | 4% Низкий | 11 месяцев назад | ||
CVSS3: 6.1 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу