Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2016-5105

около 10 лет назад

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

CVSS2: 2.3
EPSS: Низкий
redhat логотип

CVE-2016-5104

больше 10 лет назад

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-5102

около 10 лет назад

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-5096

больше 10 лет назад

Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2016-5095

больше 10 лет назад

Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2016-5094

больше 10 лет назад

Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2016-5093

больше 10 лет назад

The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted locale_get_primary_language call.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-5044

больше 10 лет назад

The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5043

больше 10 лет назад

The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5042

больше 10 лет назад

The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5041

больше 10 лет назад

dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5040

больше 10 лет назад

libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5039

больше 10 лет назад

The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5038

больше 10 лет назад

The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5037

больше 10 лет назад

The _dwarf_load_section function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5036

больше 10 лет назад

The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5035

больше 10 лет назад

The _dwarf_read_line_table_header function in dwarf_line_table_reader.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5034

больше 10 лет назад

dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file, related to relocation records.

CVSS2: 3.2
EPSS: Низкий
redhat логотип

CVE-2016-5033

больше 10 лет назад

The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS2: 1.7
EPSS: Низкий
redhat логотип

CVE-2016-5032

больше 10 лет назад

The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS2: 1.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-5105

The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

CVSS2: 2.3
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-5104

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.

CVSS2: 4.3
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5102

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

CVSS2: 4.3
2%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-5096

Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument.

CVSS2: 5.1
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5095

Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.

CVSS2: 5.1
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5094

Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.

CVSS2: 5.1
5%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5093

The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted locale_get_primary_language call.

CVSS2: 4.3
5%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5044

The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5043

The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5042

The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5041

dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.

CVSS2: 1.7
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5040

libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5039

The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5038

The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5037

The _dwarf_load_section function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.

CVSS2: 1.7
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5036

The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.

CVSS2: 1.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5035

The _dwarf_read_line_table_header function in dwarf_line_table_reader.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS2: 1.7
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5034

dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file, related to relocation records.

CVSS2: 3.2
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5033

The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

CVSS2: 1.7
3%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-5032

The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file.

CVSS2: 1.7
3%
Низкий
больше 10 лет назад

Уязвимостей на страницу