CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93121 | CVE-2016-6301 | Candidate | The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93122 | CVE-2016-6302 | Candidate | The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93123 | CVE-2016-6303 | Candidate | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93124 | CVE-2016-6304 | Candidate | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93125 | CVE-2016-6305 | Candidate | The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call. | Assigned (20160726) | None (candidate not yet proposed) | View |
Page 18625 of 20943, showing 5 records out of 104715 total, starting on record 93121, ending on 93125