CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93116  CVE-2016-6296  Candidate  Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a long first argument to the PHP xmlrpc_encode_request function.  Assigned (20160724)  None (candidate not yet proposed)    View
93117  CVE-2016-6297  Candidate  Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.  Assigned (20160724)  None (candidate not yet proposed)    View
93118  CVE-2016-6298  Candidate  The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).  Assigned (20160726)  None (candidate not yet proposed)    View
93119  CVE-2016-6299  Candidate  The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.  Assigned (20160726)  None (candidate not yet proposed)    View
93120  CVE-2016-6300  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20160726)  None (candidate not yet proposed)    View

Page 18624 of 20943, showing 5 records out of 104715 total, starting on record 93116, ending on 93120

Actions