Show filters
201 Total Results
Displaying 131-140 of 201
Sort by:
Attacker Value
Unknown

CVE-2016-2270

Disclosure Date: February 19, 2016 (last updated November 25, 2024)
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
0
Attacker Value
Unknown

CVE-2016-0753

Disclosure Date: February 16, 2016 (last updated November 25, 2024)
Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.
Attacker Value
Unknown

CVE-2016-1523

Disclosure Date: February 13, 2016 (last updated October 23, 2024)
The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1522

Disclosure Date: February 13, 2016 (last updated October 23, 2024)
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1526

Disclosure Date: February 13, 2016 (last updated October 23, 2024)
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1521

Disclosure Date: February 13, 2016 (last updated October 23, 2024)
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2015-7513

Disclosure Date: February 08, 2016 (last updated November 25, 2024)
arch/x86/kvm/x86.c in the Linux kernel before 4.4 does not reset the PIT counter values during state restoration, which allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via a zero value, related to the kvm_vm_ioctl_set_pit and kvm_vm_ioctl_set_pit2 functions.
Attacker Value
Unknown

CVE-2016-1926

Disclosure Date: January 26, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
0
Attacker Value
Unknown

CVE-2016-1572

Disclosure Date: January 22, 2016 (last updated November 25, 2024)
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.
Attacker Value
Unknown

CVE-2015-5295

Disclosure Date: January 20, 2016 (last updated November 25, 2024)
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
0