Show filters
201 Total Results
Displaying 141-150 of 201
Sort by:
Attacker Value
Unknown
CVE-2016-1494
Disclosure Date: January 13, 2016 (last updated November 25, 2024)
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
0
Attacker Value
Unknown
CVE-2015-8466
Disclosure Date: January 13, 2016 (last updated November 25, 2024)
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
0
Attacker Value
Unknown
CVE-2016-1232
Disclosure Date: January 12, 2016 (last updated November 25, 2024)
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
0
Attacker Value
Unknown
CVE-2016-1231
Disclosure Date: January 12, 2016 (last updated November 25, 2024)
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
0
Attacker Value
Unknown
CVE-2015-8400
Disclosure Date: January 12, 2016 (last updated November 25, 2024)
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
0
Attacker Value
Unknown
CVE-2015-5254
Disclosure Date: January 08, 2016 (last updated November 08, 2023)
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
0
Attacker Value
Unknown
CVE-2016-1283
Disclosure Date: January 03, 2016 (last updated November 25, 2024)
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
0
Attacker Value
Unknown
CVE-2015-8370
Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
0
Attacker Value
Unknown
CVE-2015-7217
Disclosure Date: December 16, 2015 (last updated October 05, 2023)
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.
0
Attacker Value
Unknown
CVE-2015-7218
Disclosure Date: December 16, 2015 (last updated October 05, 2023)
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.
0