Show filters
231 Total Results
Displaying 11-20 of 231
Sort by:
Attacker Value
Unknown

CVE-2016-4483

Disclosure Date: April 11, 2017 (last updated November 08, 2023)
The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627.
Attacker Value
Unknown

CVE-2016-6185

Disclosure Date: August 02, 2016 (last updated November 08, 2023)
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
Attacker Value
Unknown

CVE-2016-5387

Disclosure Date: July 19, 2016 (last updated November 08, 2023)
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Attacker Value
Unknown

CVE-2016-2178

Disclosure Date: June 20, 2016 (last updated November 08, 2023)
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.
Attacker Value
Unknown

CVE-2016-5118

Disclosure Date: June 10, 2016 (last updated November 20, 2024)
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Attacker Value
Unknown

CVE-2016-3627

Disclosure Date: May 17, 2016 (last updated February 10, 2024)
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
Attacker Value
Unknown

CVE-2016-4079

Disclosure Date: April 25, 2016 (last updated November 08, 2023)
epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.
0
Attacker Value
Unknown

CVE-2016-4082

Disclosure Date: April 25, 2016 (last updated November 08, 2023)
epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.
0
Attacker Value
Unknown

CVE-2016-4085

Disclosure Date: April 25, 2016 (last updated November 08, 2023)
Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.
0
Attacker Value
Unknown

CVE-2016-2381

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.