Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2016-7520

больше 10 лет назад

Heap-based buffer overflow in coders/hdr.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted HDR file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-7519

больше 10 лет назад

The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-7518

больше 10 лет назад

The ReadSUNImage function in coders/sun.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SUN file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-7517

больше 10 лет назад

The EncodeImage function in coders/pict.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PICT file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-7516

больше 10 лет назад

The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted VIFF file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-7515

больше 10 лет назад

The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-7514

больше 10 лет назад

The ReadPSDChannelPixels function in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-7513

больше 11 лет назад

Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-7511

почти 10 лет назад

Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-7510

почти 10 лет назад

The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2016-7498

почти 10 лет назад

OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-7480

почти 10 лет назад

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2016-7479

больше 9 лет назад

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

CVSS3: 8.1
EPSS: Средний
redhat логотип

CVE-2016-7478

почти 10 лет назад

Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2016-7466

почти 10 лет назад

Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.

CVSS3: 3
EPSS: Низкий
redhat логотип

CVE-2016-7444

почти 10 лет назад

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-7440

почти 10 лет назад

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.1
EPSS: Низкий
redhat логотип

CVE-2016-7434

больше 9 лет назад

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2016-7433

больше 9 лет назад

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 2.9
EPSS: Низкий
redhat логотип

CVE-2016-7431

больше 9 лет назад

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-7520

Heap-based buffer overflow in coders/hdr.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted HDR file.

CVSS3: 4
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7519

The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS3: 4
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7518

The ReadSUNImage function in coders/sun.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SUN file.

CVSS3: 4
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7517

The EncodeImage function in coders/pict.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PICT file.

CVSS3: 4
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7516

The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted VIFF file.

CVSS3: 4
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7515

The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.

CVSS3: 5.3
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7514

The ReadPSDChannelPixels function in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.

CVSS3: 5.3
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-7513

Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.

CVSS3: 3.3
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2016-7511

Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS3: 3.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7510

The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.

CVSS3: 3.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7498

OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.

CVSS3: 4.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7480

The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data.

CVSS3: 8.1
42%
Средний
почти 10 лет назад
redhat логотип
CVE-2016-7479

In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

CVSS3: 8.1
42%
Средний
больше 9 лет назад
redhat логотип
CVE-2016-7478

Zend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876.

CVSS3: 7.5
42%
Средний
почти 10 лет назад
redhat логотип
CVE-2016-7466

Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.

CVSS3: 3
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7444

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.

CVSS3: 5.3
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7440

The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

CVSS3: 5.1
0%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-7434

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

CVSS3: 5.3
53%
Средний
больше 9 лет назад
redhat логотип
CVE-2016-7433

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

CVSS3: 2.9
10%
Низкий
больше 9 лет назад
redhat логотип
CVE-2016-7431

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

CVSS3: 5.3
9%
Низкий
больше 9 лет назад

Уязвимостей на страницу