Show filters
75 Total Results
Displaying 41-50 of 75
Sort by:
Attacker Value
Unknown

CVE-2016-8569

Disclosure Date: February 03, 2017 (last updated November 08, 2023)
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
0
Attacker Value
Unknown

CVE-2016-7543

Disclosure Date: January 19, 2017 (last updated November 08, 2023)
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
0
Attacker Value
Unknown

CVE-2016-7545

Disclosure Date: January 19, 2017 (last updated November 08, 2023)
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
0
Attacker Value
Unknown

CVE-2016-2090

Disclosure Date: January 13, 2017 (last updated November 08, 2023)
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2016-10027

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
Attacker Value
Unknown

CVE-2016-9299

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
0
Attacker Value
Unknown

CVE-2016-8606

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
0
Attacker Value
Unknown

CVE-2016-8605

Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
0
Attacker Value
Unknown

CVE-2016-7966

Disclosure Date: December 23, 2016 (last updated November 08, 2023)
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
0
Attacker Value
Unknown

CVE-2016-7953

Disclosure Date: December 13, 2016 (last updated November 08, 2023)
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
0