Search

Found 820 results in 137ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-11683 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago There is a reachable assertion in the Internal::TiffReader::visitDirectory function in tiffvisitor.cpp of Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.
CVE-2015-1323 medium 5.5 5.5 ubuntu ubuntu 9y ago The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ub…
CVE-2017-11352 medium 6.5 6.5 FIX slesarch archdebian debian imagemagick 9y ago In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-91…
CVE-2017-9936 medium 6.5 7.5 EXPFIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CVE-2017-9815 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.7, the TIFFReadDirEntryLong8Array function in libtiff/tif_dirread.c mishandles a malloc operation, which allows attackers to cause a denial of service (memory leak within the function …
CVE-2017-9525 medium 6.7 6.7 FIX debian debianubuntu ubuntu cron_project 9y ago In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks aga…
CVE-2017-9473 medium 5.5 5.5 FIX debian debianubuntu ubuntu ytnef_project 9y ago In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
CVE-2017-9471 medium 5.5 5.5 FIX debian debianubuntu ubuntu ytnef_project 9y ago In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
CVE-2017-9404 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function OJPEGReadHeaderInfoSecTablesQTable in tif_ojpeg.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-9403 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libtiff 9y ago In LibTIFF 4.0.7, a memory leak vulnerability was found in the function TIFFReadDirEntryLong8Array in tif_dirread.c, which allows attackers to cause a denial of service via a crafted file.
CVE-2017-6512 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu file\ 9y ago Race condition in the rmtree and remove_tree functions in the File-Path module before 2.13 for Perl allows attackers to set the mode on arbitrary files via vectors involving directory-permission loos…
CVE-2017-9239 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago An issue was discovered in Exiv2 0.26. When the data structure of the structure ifd is incorrect, the program assigns pValue_ to 0x0, and the value of pValue() is 0x0. TiffImageEntry::doWriteImage wi…
CVE-2017-9210 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop…
CVE-2017-9209 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpd…
CVE-2017-9208 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qpdf_project 9y ago libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infi…
CVE-2017-9117 medium 4.0 4.0 FIX slesubuntu ubuntudebian debian libtiff 9y ago In LibTIFF 4.0.6 and possibly other versions, the program processes BMP images without verifying that biWidth and biHeight in the bitmap-information header match the actual input, as demonstrated by …
CVE-2017-8900 medium 4.6 4.6 FIX debian debianubuntu ubuntu lightdm_project 9y ago LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass intended AppArmor restrictions and visit the home directories of arbitrary users…
CVE-2017-8831 medium 6.4 6.4 FIX slesdebian debian linux-kernel 9y ago The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local users to cause a denial of service (out-of-bounds array access) or possibly hav…
CVE-2017-7613 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CVE-2017-7612 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7611 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7610 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
CVE-2017-7608 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu elfutils_project 9y ago The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted…
CVE-2016-9388 medium 5.5 5.5 FIX arch arch slesubuntu ubuntu jasper_project 9y ago The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CVE-2014-9845 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
CVE-2014-9844 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu suseimagemagick 9y ago The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
CVE-2014-9853 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu imagemagicksuse 9y ago Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
CVE-2017-6590 medium 6.3 6.3 slesubuntu ubuntudebian debian 9y ago An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the default Ubuntu login s…
CVE-2016-9963 medium 5.9 5.9 FIX arch archdebian debianubuntu ubuntu exim 10y ago Exim before 4.87.1 might allow remote attackers to obtain the private DKIM signing key via vectors related to log files and bounce messages.
CVE-2015-7977 medium 5.9 5.9 FIX slesdebian debianfedora fedora ntpnetapp 10y ago ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
CVE-2015-7973 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu ntpnetapp 10y ago NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.
CVE-2017-3313 medium 4.7 4.7 slesdebian debian rhel oraclemariadb 10y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: MyISAM). Supported versions that are affected are 5.5.53 and earlier, 5.6.34 and earlier and 5.7.16 and earlier. Dif…
CVE-2016-5824 medium 5.5 5.5 FIX sles rhelubuntu ubuntu libical_project 10y ago libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVE-2016-2375 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.
CVE-2016-2373 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious…
CVE-2016-2372 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server,…
CVE-2016-2370 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A maliciou…
CVE-2016-2369 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a denial of service vulnera…
CVE-2016-2367 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server,…
CVE-2016-2366 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious…
CVE-2016-2365 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu pidgin 10y ago A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A mali…
CVE-2016-6313 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu gnupg 10y ago The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of …
CVE-2016-9318 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu xmlsoftxmlsec_project 10y ago libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current document may be read but other files may not be opened, …
CVE-2016-7795 medium 5.5 5.5 FIX slesarch archubuntu ubuntu systemd_project 10y ago denial of service in systemd
CVE-2016-1372 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu clamav 10y ago ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
CVE-2016-1371 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu clamav 10y ago ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
CVE-2016-6306 medium 5.9 5.9 FIX slesarch archdebian debian opensslhpnodejs 10y ago The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s…
CVE-2015-8934 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted ra…
CVE-2015-8933 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafte…
CVE-2015-8932 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which trigg…
CVE-2015-8928 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
CVE-2015-8926 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.
CVE-2015-8925 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newlin…
CVE-2015-8924 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafte…
CVE-2015-8923 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
CVE-2015-8922 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu libarchivenovell 10y ago The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7…
CVE-2015-8920 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu novelllibarchive 10y ago The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
CVE-2015-8916 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libarchive 10y ago bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NU…
CVE-2016-6351 medium 6.7 6.7 FIX slesdebian debianubuntu ubuntu qemu 10y ago The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (ou…
CVE-2016-5107 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds re…
CVE-2016-5106 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of …
CVE-2016-5105 medium 4.4 4.4 FIX slesdebian debianubuntu ubuntu qemu 10y ago The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest admi…
CVE-2016-4952 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago QEMU (aka Quick Emulator), when built with VMWARE PVSCSI paravirtual SCSI bus emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds array access) via vec…
CVE-2016-5403 medium 5.5 5.5 FIX slesdebian debian rhel qemuredhat 10y ago The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without w…
CVE-2016-5440 medium 4.9 4.9 slesdebian debian rhel ibmmariadboracle 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote admi…
CVE-2016-5439 medium 4.9 4.9 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.
CVE-2016-3615 medium 5.3 5.3 slesdebian debianubuntu ubuntu mariadboracleibm 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote auth…
CVE-2016-3614 medium 5.3 5.3 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Security: Encryption.
CVE-2016-3521 medium 6.5 6.5 slesdebian debianubuntu ubuntu ibmmariadboracle 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote auth…
CVE-2016-3501 medium 6.5 6.5 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
CVE-2016-3486 medium 6.5 6.5 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.
CVE-2016-2178 medium 5.5 5.5 FIX slesarch archubuntu ubuntu opensslnodejs 10y ago The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pr…
CVE-2016-2841 medium 6.0 6.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU proces…
CVE-2016-2392 medium 6.5 6.5 FIX ubuntu ubuntudebian debian qemu 10y ago The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administr…
CVE-2016-2391 medium 5.0 5.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process …
CVE-2012-6702 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu libexpat_project 10y ago Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors in…
CVE-2016-5337 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qemu 10y ago The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control informat…
CVE-2016-5238 medium 4.4 4.4 FIX slesubuntu ubuntudebian debian qemu 10y ago The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from t…
CVE-2016-5104 medium 5.3 5.3 FIX slesarch archdebian debian libimobiledevice 10y ago The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connect…
CVE-2016-2833 medium 6.1 6.1 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks vi…
CVE-2016-2832 medium 4.3 4.3 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
CVE-2016-2829 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or…
CVE-2016-2825 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
CVE-2016-2822 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
CVE-2016-4429 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu gnu 10y ago Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecif…
CVE-2016-1582 medium 5.5 5.5 FIX ubuntu ubuntudebian debian canonical 10y ago LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container di…
CVE-2016-1581 medium 5.5 5.5 FIX ubuntu ubuntudebian debian canonical 10y ago LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecifi…
CVE-2016-1702 medium 6.5 6.5 rhelubuntu ubuntudebian debian google 10y ago The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial…
CVE-2016-1699 medium 6.5 6.5 ubuntu ubuntu rheldebian debian google 10y ago WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl paramet…
CVE-2016-1692 medium 5.3 5.3 suse susedebian debianubuntu ubuntu google 10y ago WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet downl…
CVE-2016-1689 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified o…
CVE-2016-1688 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to caus…
CVE-2016-1682 medium 6.1 6.1 suse susedebian debianubuntu ubuntu google 10y ago The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote…
CVE-2016-1677 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeU…
CVE-2016-4804 medium 6.2 6.2 FIX slesdebian debiansuse suse dosfstools_project 10y ago The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_f…
CVE-2015-8872 medium 6.2 6.2 FIX slesdebian debiansuse suse dosfstools_project 10y ago The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clu…
CVE-2016-4454 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash)…
CVE-2016-4453 medium 4.4 4.4 FIX slesdebian debianubuntu ubuntu qemu 10y ago The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.
CVE-2016-4020 medium 6.5 6.5 FIX sles rhelubuntu ubuntu qemuredhat 10y ago The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory …
CVE-2016-4037 medium 6.0 6.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous tra…