Show filters
174 Total Results
Displaying 61-70 of 174
Sort by:
Attacker Value
Unknown
CVE-2016-1678
Disclosure Date: June 05, 2016 (last updated November 08, 2023)
objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.
0
Attacker Value
Unknown
CVE-2016-4485
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message.
0
Attacker Value
Unknown
CVE-2016-4569
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.
0
Attacker Value
Unknown
CVE-2016-4486
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.
0
Attacker Value
Unknown
CVE-2016-4482
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
0
Attacker Value
Unknown
CVE-2016-4913
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
0
Attacker Value
Unknown
CVE-2016-4578
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.
0
Attacker Value
Unknown
CVE-2016-3718
Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
0
Attacker Value
Unknown
CVE-2016-3715
Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
0
Attacker Value
Unknown
CVE-2016-3714
Disclosure Date: May 05, 2016 (last updated September 11, 2024)
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
0