Show filters
263 Total Results
Displaying 21-30 of 263
Sort by:
Attacker Value
Unknown
CVE-2015-8768
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmrow app for Ubuntu phone.
0
Attacker Value
Unknown
CVE-2015-5261
Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
0
Attacker Value
Unknown
CVE-2015-5260
Disclosure Date: June 07, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter.
0
Attacker Value
Unknown
CVE-2016-1576
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.
0
Attacker Value
Unknown
CVE-2016-1575
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.
0
Attacker Value
Unknown
CVE-2015-8325
Disclosure Date: May 01, 2016 (last updated November 25, 2024)
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted environment for the /bin/login program, as demonstrated by an LD_PRELOAD environment variable.
0
Attacker Value
Unknown
CVE-2016-0661
Disclosure Date: April 21, 2016 (last updated November 25, 2024)
Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.
0
Attacker Value
Unknown
CVE-2011-4600
Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.
0
Attacker Value
Unknown
CVE-2015-5247
Disclosure Date: April 14, 2016 (last updated November 25, 2024)
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.
0
Attacker Value
Unknown
CVE-2015-8560
Disclosure Date: April 14, 2016 (last updated November 25, 2024)
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
0