Show filters
201 Total Results
Displaying 101-110 of 201
Sort by:
Attacker Value
Unknown

CVE-2016-2146

Disclosure Date: April 15, 2016 (last updated November 25, 2024)
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
0
Attacker Value
Unknown

CVE-2016-2145

Disclosure Date: April 15, 2016 (last updated November 25, 2024)
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.
0
Attacker Value
Unknown

CVE-2015-8540

Disclosure Date: April 14, 2016 (last updated November 08, 2023)
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2016-0787

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
0
Attacker Value
Unknown

CVE-2016-0739

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
0
Attacker Value
Unknown

CVE-2016-2228

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.
0
Attacker Value
Unknown

CVE-2015-8807

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
0
Attacker Value
Unknown

CVE-2016-3159

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
0
Attacker Value
Unknown

CVE-2016-3158

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.
0
Attacker Value
Unknown

CVE-2016-3068

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
0