Show filters
452 Total Results
Displaying 61-70 of 452
Sort by:
Attacker Value
Unknown

CVE-2016-8635

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
0
Attacker Value
Unknown

CVE-2016-9573

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
0
Attacker Value
Unknown

CVE-2017-7518

Disclosure Date: July 30, 2018 (last updated November 08, 2023)
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate their privileges inside the guest. Linux guests are not affected by this.
0
Attacker Value
Unknown

CVE-2016-9603

Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU process or, potentially, execute arbitrary code on the host with privileges of the QEMU process.
0
Attacker Value
Unknown

CVE-2016-9578

Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
0
Attacker Value
Unknown

CVE-2017-15097

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
0
Attacker Value
Unknown

CVE-2016-9577

Disclosure Date: July 27, 2018 (last updated November 08, 2023)
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
0
Attacker Value
Unknown

CVE-2017-15101

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
0
Attacker Value
Unknown

CVE-2017-2620

Disclosure Date: July 27, 2018 (last updated November 08, 2023)
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary code on host with privileges of the QEMU process.
0
Attacker Value
Unknown

CVE-2017-2618

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
0