Show filters
201 Total Results
Displaying 61-70 of 201
Sort by:
Attacker Value
Unknown
CVE-2016-8606
Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
0
Attacker Value
Unknown
CVE-2016-8605
Disclosure Date: January 12, 2017 (last updated November 08, 2023)
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mode argument would create directories as 0777. This is fixed in Guile 2.0.13. Prior versions are affected.
0
Attacker Value
Unknown
CVE-2016-2312
Disclosure Date: December 23, 2016 (last updated November 25, 2024)
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
0
Attacker Value
Unknown
CVE-2016-2334
Disclosure Date: December 13, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
0
Attacker Value
Unknown
CVE-2016-6323
Disclosure Date: October 07, 2016 (last updated November 08, 2023)
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
0
Attacker Value
Unknown
CVE-2016-7167
Disclosure Date: October 07, 2016 (last updated November 08, 2023)
Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2016-7163
Disclosure Date: September 21, 2016 (last updated November 08, 2023)
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
0
Attacker Value
Unknown
CVE-2016-5157
Disclosure Date: September 11, 2016 (last updated November 08, 2023)
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
0
Attacker Value
Unknown
CVE-2016-5404
Disclosure Date: September 07, 2016 (last updated November 25, 2024)
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
0
Attacker Value
Unknown
CVE-2016-6855
Disclosure Date: September 07, 2016 (last updated November 08, 2023)
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.
0