Search

Found 1,663 results in 247ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-3074 critical 9.8 10.0 EXPFIX slesdebian debiansuse suse libgdphp 10y ago Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed g…
CVE-2016-4054 high 8.1 8.1 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
CVE-2016-4053 low 3.7 3.7 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and…
CVE-2016-4052 high 8.1 8.1 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (…
CVE-2016-4051 high 8.8 8.8 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports wi…
CVE-2016-2115 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB c…
CVE-2016-2114 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle att…
CVE-2016-2113 high 7.4 7.4 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS and HTTPS servers and …
CVE-2016-2112 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-midd…
CVE-2016-2111 medium 6.3 6.3 FIX slesubuntu ubuntudebian debian samba 10y ago The NETLOGON service in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2, when a domain controller is configured, allows remote attackers to spoof the computer name of a se…
CVE-2016-2110 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by mo…
CVE-2015-5370 medium 5.9 5.9 FIX slesubuntu ubuntudebian debian samba 10y ago Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not properly implement the DCE-RPC layer, which allows remote attackers to perform protocol-downgrade attacks, cause a…
CVE-2013-7449 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu xchathexchat_project 10y ago The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows m…
CVE-2016-0668 medium 4.1 4.1 slessuse susedebian debian oraclemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors r…
CVE-2016-0665 medium 5.5 5.5 sles rhelubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.
CVE-2016-0661 medium 4.7 4.7 sles rhelubuntu ubuntu oracle 10y ago Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
CVE-2016-0642 medium 4.7 4.7 sles rhelsuse suse oraclesusemariadb 10y ago Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.
CVE-2015-7802 medium 5.5 5.5 FIX ubuntu ubuntudebian debian optipng_project 10y ago gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
CVE-2015-7801 high 8.8 8.8 FIX ubuntu ubuntudebian debian optipng_project 10y ago Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
CVE-2015-8779 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possib…
CVE-2015-8778 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu gnususe 10y ago Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the s…
CVE-2015-8776 critical 9.1 9.1 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive informatio…
CVE-2015-7511 low 2.0 2.0 FIX slesdebian debianubuntu ubuntu gnupg 10y ago Libgcrypt before 1.6.5 does not properly perform elliptic-point curve multiplication during decryption, which makes it easier for physically proximate attackers to extract ECDH keys by measuring elec…
CVE-2014-9765 high 8.8 8.8 FIX debian debianubuntu ubuntususe suse xdelta 10y ago Buffer overflow in the main_get_appheader function in xdelta3-main.h in xdelta3 before 3.0.9 allows remote attackers to execute arbitrary code via a crafted input file.
CVE-2014-9761 critical 9.8 9.8 FIX debian debianfedora fedoraubuntu ubuntu susegnu 10y ago Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbi…
CVE-2016-3941 medium 5.5 5.5 FIX ubuntu ubuntudebian debian videolan 10y ago Buffer overflow in the AStreamPeekStream function in input/stream.c in VideoLAN VLC media player before 2.2.0 allows remote attackers to cause a denial of service (crash) via a crafted wav file, rela…
CVE-2016-1659 critical 9.8 9.8 debian debianubuntu ubuntususe suse google 10y ago Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1655 high 8.8 8.8 debian debianubuntu ubuntususe suse google 10y ago Google Chrome before 50.0.2661.75 does not properly consider that frame removal may occur during callback execution, which allows remote attackers to cause a denial of service (use-after-free) or pos…
CVE-2016-1654 medium 6.5 6.5 debian debianubuntu ubuntususe suse google 10y ago The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unk…
CVE-2016-1653 high 8.8 8.8 debian debianubuntu ubuntususe suse google 10y ago The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecifie…
CVE-2016-3961 medium 5.5 5.5 FIX debian debianubuntu ubuntu 10y ago Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to…
CVE-2015-5247 medium 6.5 6.5 FIX debian debianubuntu ubuntu redhat 10y ago The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unl…
CVE-2011-4600 medium 5.9 5.9 FIX debian debianubuntu ubuntu redhat 10y ago The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow rem…
CVE-2015-8560 high 7.3 7.3 FIX debian debianubuntu ubuntu linuxfoundation 10y ago Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a …
CVE-2016-0739 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu libssh 10y ago libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-i…
CVE-2015-3146 high 7.5 7.5 FIX debian debianubuntu ubuntufedora fedora libssh 10y ago The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (…
CVE-2016-3982 high 8.8 8.8 FIX suse suseubuntu ubuntudebian debian optipng_project 10y ago Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly e…
CVE-2016-3981 high 7.8 7.8 FIX ubuntu ubuntudebian debian optipng_project 10y ago Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or p…
CVE-2016-2191 medium 6.5 6.5 FIX suse suseubuntu ubuntudebian debian optipng 10y ago The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a craf…
CVE-2015-8552 medium 4.4 4.4 FIX debian debianubuntu ubuntu 10y ago The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messag…
CVE-2015-7545 critical 9.8 9.8 FIX slesdebian debiansuse suse git_projectredhat 10y ago The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed prot…
CVE-2016-2116 medium 5.7 5.7 FIX slesarch archubuntu ubuntu jasper_project 10y ago Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG…
CVE-2016-1577 high 7.6 7.6 FIX slesarch archubuntu ubuntu jasper_project 10y ago Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a cr…
CVE-2014-9766 critical 9.8 9.8 FIX slesubuntu ubuntudebian debian pixman 10y ago Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…
CVE-2016-2118 high 7.5 7.5 FIX slesubuntu ubuntudebian debian samba 10y ago The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers …
CVE-2016-3157 high 7.8 7.8 FIX debian debianubuntu ubuntu 10y ago The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which allows local guest OS users to gain privileges, cause…
CVE-2016-2857 high 8.4 8.4 FIX slesubuntu ubuntudebian debian qemuredhat 10y ago The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
CVE-2016-2381 high 7.5 7.5 FIX slessuse suseubuntu ubuntu perloracle 10y ago Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.
CVE-2016-2510 high 8.1 8.1 FIX slesdebian debianubuntu ubuntu beanshell 10y ago Improper Input Validation in BeanShell
CVE-2016-2858 medium 6.5 6.5 FIX slesubuntu ubuntudebian debian qemu 10y ago QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbit…
CVE-2016-3947 high 8.2 8.2 FIX slesubuntu ubuntudebian debian squid-cache 10y ago Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performan…
CVE-2016-3679 high 8.8 8.8 suse suseubuntu ubuntu google 10y ago Multiple unspecified vulnerabilities in Google V8 before 4.9.385.33, as used in Google Chrome before 49.0.2623.108, allow attackers to cause a denial of service or possibly have other impact via unkn…
CVE-2016-1649 high 8.8 8.8 suse suseubuntu ubuntudebian debian google 10y ago The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certain data-type mismatch, which allows remote attacker…
CVE-2016-1647 high 8.8 8.8 suse suseubuntu ubuntudebian debian google 10y ago Use-after-free vulnerability in the RenderWidgetHostImpl::Destroy function in content/browser/renderer_host/render_widget_host_impl.cc in the Navigation implementation in Google Chrome before 49.0.26…
CVE-2016-1762 high 8.1 8.1 FIX debian debianmacos macosubuntu ubuntu applexmlsoftmcafee 10y ago The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.
CVE-2016-2856 high 8.4 9.4 EXPFIX debian debianubuntu ubuntu gnu 10y ago pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc pack…
CVE-2015-7560 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu samba 10y ago The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by usi…
CVE-2016-1286 high 8.6 8.6 FIX slesdebian debianubuntu ubuntu iscsusejuniper 10y ago named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME r…
CVE-2016-1285 medium 6.8 6.8 FIX slesdebian debiansuse suse iscsusejuniper 10y ago named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service …
CVE-2016-2774 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu isc 10y ago ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertio…
CVE-2016-0797 high 7.5 7.5 FIX debian debianubuntu ubuntu opensslnodejs 10y ago Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly …
CVE-2016-0705 critical 9.8 9.8 FIX debian debianubuntu ubuntu oracleopenssl 10y ago Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory…
CVE-2016-0702 medium 5.1 5.1 FIX debian debianubuntu ubuntu opensslnodejs 10y ago The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiati…
CVE-2016-0763 medium 6.3 6.3 FIX debian debianubuntu ubuntu apache 10y ago The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLink…
CVE-2016-0714 high 8.8 8.8 FIX debian debianubuntu ubuntu apache 10y ago The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticat…
CVE-2016-0706 medium 4.3 4.3 FIX slesdebian debianubuntu ubuntu apache 10y ago Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/Restrict…
CVE-2015-5351 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu apache 10y ago The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, wh…
CVE-2015-5346 high 8.1 8.1 FIX slesdebian debianubuntu ubuntu apache 10y ago Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the sam…
CVE-2015-5345 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu apache 10y ago The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which a…
CVE-2015-5174 medium 4.3 4.3 slesdebian debianubuntu ubuntu apache 10y ago Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
CVE-2015-8805 critical 9.8 9.8 FIX debian debianubuntu ubuntususe suse nettle_project 10y ago The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
CVE-2015-8804 critical 9.8 9.8 FIX ubuntu ubuntususe susedebian debian nettle_project 10y ago x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to…
CVE-2015-8803 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu nettle_project 10y ago The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allo…
CVE-2016-0795 high 7.8 7.8 FIX debian debianubuntu ubuntu libreoffice 10y ago LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (l…
CVE-2016-0794 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu libreoffice 10y ago The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
CVE-2015-7547 high 8.1 9.1 EXPFIX debian debianubuntu ubuntususe suse hpsophossuse 10y ago Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a den…
CVE-2016-0773 high 7.5 7.5 slesdebian debianubuntu ubuntu postgresql 10y ago PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow a…
CVE-2016-0766 high 8.8 8.8 slesdebian debianubuntu ubuntu postgresql 10y ago PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) fo…
CVE-2013-7447 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu 10y ago Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, all…
CVE-2016-0747 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu f5applenginx 10y ago The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) v…
CVE-2016-0746 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu f5applenginx 10y ago Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspeci…
CVE-2016-0742 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu f5appleredhat 10y ago The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVE-2016-2073 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu xmlsoft 11y ago The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.
CVE-2016-2330 high 8.8 8.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified…
CVE-2016-2326 high 8.8 8.8 FIX debian debianubuntu ubuntu ffmpeg 11y ago Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a c…
CVE-2016-0728 high 7.8 8.8 EXPFIX slesdebian debianubuntu ubuntu hp 11y ago The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or…
CVE-2015-8767 medium 6.2 6.2 FIX slesdebian debianubuntu ubuntu 11y ago net/sctp/sm_sideeffect.c in the Linux kernel before 4.3 does not properly manage the relationship between a lock and a socket, which allows local users to cause a denial of service (deadlock) via a c…
CVE-2015-8539 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 11y ago The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to se…
CVE-2015-7513 medium 6.5 6.5 FIX slesdebian debianfedora fedora 11y ago arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and ho…
CVE-2016-1947 medium 4.7 4.7 ubuntu ubuntususe suse mozilla 11y ago Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of re…
CVE-2016-0755 high 7.3 7.3 FIX debian debianubuntu ubuntu haxx 11y ago The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow remote attackers to authenticate as other users vi…
CVE-2016-2047 medium 5.9 5.9 slesdebian debianubuntu ubuntu mariadboracle 11y ago The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 …
CVE-2016-1572 high 8.4 8.4 FIX slesdebian debianfedora fedora ecryptfs 11y ago mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated…
CVE-2016-0616 medium 4.0 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via u…
CVE-2016-0611 medium 4.0 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2016-0610 low 3.5 slesdebian debianubuntu ubuntu oraclemariadb 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related t…
CVE-2016-0609 low 1.7 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0608 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…
CVE-2016-0607 low 2.8 slesubuntu ubuntususe suse oracle 11y ago Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and 5.7.9 allows remote authenticated users to affect availability via unknown vectors related to replication.
CVE-2016-0606 low 3.5 slesdebian debianubuntu ubuntu mariadboracle 11y ago Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated use…