Show filters
117 Total Results
Displaying 101-110 of 117
Sort by:
Attacker Value
Unknown
CVE-2016-2849
Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
0
Attacker Value
Unknown
CVE-2016-4008
Disclosure Date: May 05, 2016 (last updated November 08, 2023)
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
0
Attacker Value
Unknown
CVE-2016-3074
Disclosure Date: April 26, 2016 (last updated November 25, 2024)
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2016-4002
Disclosure Date: April 26, 2016 (last updated November 25, 2024)
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitrary code via a packet larger than 1514 bytes.
0
Attacker Value
Unknown
CVE-2016-3960
Disclosure Date: April 19, 2016 (last updated November 25, 2024)
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
0
Attacker Value
Unknown
CVE-2015-8106
Disclosure Date: April 18, 2016 (last updated November 25, 2024)
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.
0
Attacker Value
Unknown
CVE-2016-3071
Disclosure Date: April 18, 2016 (last updated November 25, 2024)
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
0
Attacker Value
Unknown
CVE-2016-3144
Disclosure Date: April 15, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
0
Attacker Value
Unknown
CVE-2016-0729
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.
0
Attacker Value
Unknown
CVE-2016-1285
Disclosure Date: March 09, 2016 (last updated December 01, 2023)
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
0