Show filters
263 Total Results
Displaying 21-30 of 263
Sort by:
Attacker Value
Unknown

CVE-2015-8768

Disclosure Date: February 13, 2017 (last updated November 26, 2024)
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.
0
Attacker Value
Unknown

CVE-2015-5261

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
0
Attacker Value
Unknown

CVE-2015-5260

Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
0
Attacker Value
Unknown

CVE-2016-1576

Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
Attacker Value
Unknown

CVE-2016-1575

Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
Attacker Value
Unknown

CVE-2015-8325

Disclosure Date: May 01, 2016 (last updated November 25, 2024)
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
0
Attacker Value
Unknown

CVE-2016-0661

Disclosure Date: April 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
0
Attacker Value
Unknown

CVE-2011-4600

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
0
Attacker Value
Unknown

CVE-2015-5247

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
0
Attacker Value
Unknown

CVE-2015-8560

Disclosure Date: April 14, 2016 (last updated November 25, 2024)
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
0