|
265461
|
7.5 |
HIGH
Network
|
quagga opensuse
|
quagga leap opensuse
|
The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and d…
|
CWE-20
Improper Input Validation
|
CVE-2016-4049
|
2024-11-21 11:51 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265462
|
6.0 |
MEDIUM
Local
|
fedoraproject canonical qemu debian
|
fedora ubuntu_linux qemu debian_linux
|
The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous tra…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-4037
|
2024-11-21 11:51 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265463
|
8.6 |
HIGH
Network
|
qemu canonical fedoraproject debian
|
qemu ubuntu_linux fedora debian_linux
|
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cau…
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-4001
|
2024-11-21 11:51 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265464
|
7.5 |
HIGH
Network
|
opensuse golang fedoraproject
|
leap go fedora
|
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a …
|
CWE-20
Improper Input Validation
|
CVE-2016-3959
|
2024-11-21 11:51 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265465
|
7.8 |
HIGH
Local
|
golang
|
go
|
Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, related to use …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-3958
|
2024-11-21 11:51 |
2016-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265466
|
9.8 |
CRITICAL
Network
|
php opensuse
|
php leap opensuse
|
Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string,…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-4346
|
2024-11-21 11:51 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265467
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other i…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-4345
|
2024-11-21 11:51 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265468
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argumen…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-4344
|
2024-11-21 11:51 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265469
|
8.8 |
HIGH
Network
|
php opensuse
|
php opensuse
|
The phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink files, which allows remote attackers to cause a denial of service…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2016-4343
|
2024-11-21 11:51 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265470
|
8.8 |
HIGH
Network
|
opensuse php
|
leap php
|
ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompressed data, which allows remote attackers to cause a denial of service (heap memor…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4342
|
2024-11-21 11:51 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|