Search

Found 1,419 results in 234ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-5421 high 8.1 8.1 FIX slesdebian debiansuse suse haxx 10y ago Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
CVE-2016-6128 high 7.5 7.5 FIX slesdebian debiansuse suse libgdphp 10y ago The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application cras…
CVE-2016-6232 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu kde 10y ago Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, r…
CVE-2016-5403 medium 5.5 5.5 FIX slesdebian debian rhel qemuredhat 10y ago The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without w…
CVE-2016-6185 high 7.8 7.8 FIX slesfedora fedoradebian debian perl 10y ago The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under…
CVE-2016-5131 high 8.8 8.8 FIX slesarch archdebian debian googlexmlsoft 10y ago Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via…
CVE-2016-6224 low 3.3 3.3 FIX slesdebian debianubuntu ubuntu ecryptfs 10y ago ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obt…
CVE-2015-8946 low 3.3 3.3 FIX slesdebian debianubuntu ubuntu ecryptfs 10y ago ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local …
CVE-2016-5440 medium 4.9 4.9 slesdebian debian rhel ibmmariadboracle 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote admi…
CVE-2016-5439 medium 4.9 4.9 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.
CVE-2016-3615 medium 5.3 5.3 slesdebian debianubuntu ubuntu mariadboracleibm 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote auth…
CVE-2016-3614 medium 5.3 5.3 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Security: Encryption.
CVE-2016-3521 medium 6.5 6.5 slesdebian debianubuntu ubuntu ibmmariadboracle 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote auth…
CVE-2016-3501 medium 6.5 6.5 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.
CVE-2016-3486 medium 6.5 6.5 ubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.
CVE-2016-3477 high 8.1 8.1 slesdebian debianubuntu ubuntu ibmoraclemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users…
CVE-2016-5387 high 8.1 8.1 FIX debian debian slesfedora fedora apachehporacle 10y ago The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh…
CVE-2016-4324 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu libreoffice 10y ago Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
CVE-2016-3092 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu apachehp 10y ago The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, all…
CVE-2016-4998 high 7.1 8.1 EXPFIX slesdebian debian linux-kernel 10y ago The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a denial of service (out-of-bounds read) or possibly obtain sens…
CVE-2016-4997 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel novell 10y ago The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of …
CVE-2016-1704 high 8.8 8.8 sles rhelsuse suse googlenovell 10y ago Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-5360 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu haproxy 10y ago HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impa…
CVE-2016-4971 high 8.8 9.8 EXPFIX slesubuntu ubuntudebian debian gnu 10y ago GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
CVE-2016-4472 high 8.1 8.1 FIX slesdebian debianubuntu ubuntu libexpat_projectmcafeepython 10y ago The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via …
CVE-2015-8899 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu thekelleys 10y ago Dnsmasq before 2.76 allows remote servers to cause a denial of service (crash) via a reply with an empty DNS address that has an (1) A or (2) AAAA record defined locally.
CVE-2016-5829 high 7.8 7.8 FIX slesdebian debian linux-kernel 10y ago Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly hav…
CVE-2016-5828 high 7.8 7.8 FIX slesdebian debian linux-kernel 10y ago The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service…
CVE-2016-1583 high 7.8 8.8 EXPFIX slesdebian debian linux-kernel novell 10y ago The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vecto…
CVE-2016-0758 high 7.8 7.8 FIX slesdebian debian rhel 10y ago Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
CVE-2016-2178 medium 5.5 5.5 FIX slesarch archubuntu ubuntu opensslnodejs 10y ago The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pr…
CVE-2016-5300 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu libexpat_project 10y ago The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an …
CVE-2016-2841 medium 6.0 6.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU proces…
CVE-2016-2392 medium 6.5 6.5 FIX ubuntu ubuntudebian debian qemu 10y ago The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administr…
CVE-2016-2391 medium 5.0 5.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process …
CVE-2012-6702 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu libexpat_project 10y ago Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors in…
CVE-2016-5338 high 7.8 7.8 FIX slesubuntu ubuntudebian debian qemu 10y ago The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QE…
CVE-2016-5337 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian qemu 10y ago The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control informat…
CVE-2016-5238 medium 4.4 4.4 FIX slesubuntu ubuntudebian debian qemu 10y ago The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from t…
CVE-2016-4579 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnupg 10y ago Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl…
CVE-2016-4574 high 7.5 7.5 FIX debian debianubuntu ubuntususe suse gnupg 10y ago Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded…
CVE-2016-4356 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnupg 10y ago The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after in…
CVE-2016-4355 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnupg 10y ago Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4354 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnupg 10y ago ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
CVE-2016-4353 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnupg 10y ago ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
CVE-2016-3698 high 8.1 8.1 FIX slesdebian debian rhel libndp 10y ago libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks o…
CVE-2016-5104 medium 5.3 5.3 FIX slesarch archdebian debian libimobiledevice 10y ago The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connect…
CVE-2016-2834 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu mozillanovell 10y ago Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly…
CVE-2016-2833 medium 6.1 6.1 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks vi…
CVE-2016-2832 medium 4.3 4.3 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
CVE-2016-2831 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (…
CVE-2016-2829 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or…
CVE-2016-2828 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after des…
CVE-2016-2825 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
CVE-2016-2822 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
CVE-2016-2821 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu mozilla 10y ago Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execu…
CVE-2016-2819 high 8.8 9.8 EXPFIX slesdebian debianubuntu ubuntu mozilla 10y ago Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fr…
CVE-2016-2818 high 8.8 8.8 FIX slesdebian debian rhel mozillanovell 10y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and a…
CVE-2016-2815 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu mozillanovell 10y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe…
CVE-2016-4429 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu gnu 10y ago Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecif…
CVE-2016-4449 high 7.1 7.1 FIX slesdebian debianubuntu ubuntu xmlsoft 10y ago XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, allows context-dependent attackers to read arbitra…
CVE-2016-4447 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu hpapplexmlsoft 10y ago The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted …
CVE-2016-1582 medium 5.5 5.5 FIX ubuntu ubuntudebian debian canonical 10y ago LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container di…
CVE-2016-1581 medium 5.5 5.5 FIX ubuntu ubuntudebian debian canonical 10y ago LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecifi…
CVE-2016-4450 high 7.5 7.5 FIX slesubuntu ubuntudebian debian f5nginx 10y ago os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, inv…
CVE-2015-5261 high 7.1 7.1 FIX sles rhelubuntu ubuntu spice_project 10y ago Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
CVE-2015-5260 high 7.8 7.8 FIX sles rhelubuntu ubuntu spice_project 10y ago Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host v…
CVE-2015-8806 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu xmlsoft 10y ago Denial of service or RCE from libxml2 and libxslt
CVE-2016-1703 high 8.8 8.8 rhelubuntu ubuntudebian debian google 10y ago Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1702 medium 6.5 6.5 rhelubuntu ubuntudebian debian google 10y ago The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial…
CVE-2016-1699 medium 6.5 6.5 ubuntu ubuntu rheldebian debian google 10y ago WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl paramet…
CVE-2016-1697 high 8.8 8.8 rhelubuntu ubuntudebian debian google 10y ago The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detac…
CVE-2016-1695 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1692 medium 5.3 5.3 suse susedebian debianubuntu ubuntu google 10y ago WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet downl…
CVE-2016-1691 high 7.5 7.5 suse susedebian debianubuntu ubuntu google 10y ago Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified o…
CVE-2016-1689 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified o…
CVE-2016-1688 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to caus…
CVE-2016-1683 high 7.5 7.5 FIX debian debiansuse suseubuntu ubuntu xmlsoftgoogle 10y ago numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory acc…
CVE-2016-1682 medium 6.1 6.1 suse susedebian debianubuntu ubuntu google 10y ago The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote…
CVE-2016-1680 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or p…
CVE-2016-1679 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote a…
CVE-2016-1678 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (hea…
CVE-2016-1677 medium 6.5 6.5 suse susedebian debianubuntu ubuntu google 10y ago uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeU…
CVE-2016-1675 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to Fra…
CVE-2016-1673 high 8.8 8.8 suse susedebian debianubuntu ubuntu google 10y ago Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
CVE-2016-4804 medium 6.2 6.2 FIX slesdebian debiansuse suse dosfstools_project 10y ago The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_f…
CVE-2015-8872 medium 6.2 6.2 FIX slesdebian debiansuse suse dosfstools_project 10y ago The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clu…
CVE-2016-5126 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu qemuredhat 10y ago Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code vi…
CVE-2016-4454 medium 6.0 6.0 FIX slesdebian debianubuntu ubuntu qemu 10y ago The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash)…
CVE-2016-4453 medium 4.4 4.4 FIX slesdebian debianubuntu ubuntu qemu 10y ago The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.
CVE-2016-3075 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack …
CVE-2016-4020 medium 6.5 6.5 FIX sles rhelubuntu ubuntu qemuredhat 10y ago The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory …
CVE-2016-4037 medium 6.0 6.0 FIX slesubuntu ubuntudebian debian qemu 10y ago The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous tra…
CVE-2016-4001 high 8.6 8.6 FIX slesubuntu ubuntudebian debian qemu 10y ago Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cau…
CVE-2016-4951 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 10y ago The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference a…
CVE-2016-4913 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu novell 10y ago The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensit…
CVE-2016-4805 high 7.8 7.8 FIX slesdebian debian rhel novell 10y ago Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or pos…
CVE-2016-4794 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 10y ago Use-after-free vulnerability in mm/percpu.c in the Linux kernel through 4.6 allows local users to cause a denial of service (BUG) or possibly have unspecified other impact via crafted use of the mmap…
CVE-2016-4581 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu 10y ago fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL …
CVE-2016-4580 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu 10y ago The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data structure, which allows attackers to obtain sensitive in…