Show filters
71 Total Results
Displaying 61-70 of 71
Sort by:
Attacker Value
Unknown

CVE-2016-2107

Disclosure Date: May 05, 2016 (last updated February 17, 2024)
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
Attacker Value
Unknown

CVE-2016-3427

Disclosure Date: April 21, 2016 (last updated June 28, 2024)
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
Attacker Value
Unknown

CVE-2016-2857

Disclosure Date: April 12, 2016 (last updated November 25, 2024)
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
Attacker Value
Unknown

CVE-2016-1285

Disclosure Date: March 09, 2016 (last updated December 01, 2023)
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Attacker Value
Unknown

CVE-2016-1286

Disclosure Date: March 09, 2016 (last updated December 01, 2023)
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.
Attacker Value
Unknown

CVE-2015-3281

Disclosure Date: July 06, 2015 (last updated May 30, 2024)
The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data, which allows remote attackers to obtain sensitive information (uninitialized memory contents of previous requests) via a crafted request.
0
Attacker Value
Unknown

CVE-2015-3209

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
0
Attacker Value
Unknown

CVE-2014-3615

Disclosure Date: November 01, 2014 (last updated October 05, 2023)
The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.
0
Attacker Value
Unknown

CVE-2014-7230

Disclosure Date: October 08, 2014 (last updated October 05, 2023)
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
0
Attacker Value
Unknown

CVE-2014-3621

Disclosure Date: October 02, 2014 (last updated October 05, 2023)
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.
0