Show filters
505 Total Results
Displaying 61-70 of 505
Sort by:
Attacker Value
Unknown

CVE-2014-9765

Disclosure Date: April 19, 2016 (last updated November 25, 2024)
Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
0
Attacker Value
Unknown

CVE-2016-0787

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
0
Attacker Value
Unknown

CVE-2016-2191

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.
0
Attacker Value
Unknown

CVE-2016-3068

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
0
Attacker Value
Unknown

CVE-2016-3982

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-3630

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Attacker Value
Unknown

CVE-2016-3069

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
0
Attacker Value
Unknown

CVE-2015-8551

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X capable physical PCI device and a crafted sequence of XEN_PCI_OP_* operations, aka "Linux pciback missing sanity checks."
Attacker Value
Unknown

CVE-2015-8080

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow.
Attacker Value
Unknown

CVE-2016-2381

Disclosure Date: April 08, 2016 (last updated November 25, 2024)
Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.