|
267151
|
7.5 |
HIGH
Network
|
debian fedoraproject botan_project
|
debian_linux fedora botan
|
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret ke…
|
CWE-200
Information Exposure
|
CVE-2016-2849
|
2024-11-21 11:48 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267152
|
9.8 |
CRITICAL
Network
|
botan_project
|
botan
|
Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2196
|
2024-11-21 11:48 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267153
|
9.8 |
CRITICAL
Network
|
botan_project debian
|
botan debian_linux
|
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point,…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2195
|
2024-11-21 11:48 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267154
|
7.5 |
HIGH
Network
|
debian botan_project
|
debian_linux botan
|
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a c…
|
CWE-20
Improper Input Validation
|
CVE-2016-2194
|
2024-11-21 11:48 |
2016-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267155
|
7.0 |
HIGH
Local
|
google
|
android
|
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles updates of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspec…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2462
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267156
|
7.0 |
HIGH
Local
|
google
|
android
|
OpenSSLCipher.java in Conscrypt in Android 6.x before 2016-05-01 mishandles resets of the Additional Authenticated Data (AAD) array, which allows attackers to spoof message authentication via unspeci…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2461
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267157
|
5.5 |
MEDIUM
Local
|
google
|
android
|
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive info…
|
CWE-200
Information Exposure
|
CVE-2016-2460
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267158
|
5.5 |
MEDIUM
Local
|
google
|
android
|
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structures, which allows attackers to obtain sensitive info…
|
CWE-200
Information Exposure
|
CVE-2016-2459
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267159
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attachments, which allows attackers to obtain sensitive …
|
CWE-200
Information Exposure
|
CVE-2016-2458
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267160
|
5.5 |
MEDIUM
Local
|
google
|
android
|
server/pm/UserManagerService.java in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 allows attackers to bypass intended restrictions on Wi-Fi configuration changes…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2457
|
2024-11-21 11:48 |
2016-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|