Show filters
508 Total Results
Displaying 71-80 of 508
Sort by:
Attacker Value
Unknown
CVE-2016-5829
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local users to cause a denial of service or possibly have unspecified other impact via a crafted (1) HIDIOCGUSAGES or (2) HIDIOCSUSAGES ioctl call.
0
Attacker Value
Unknown
CVE-2016-5828
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishandles transactional state, which allows local users to cause a denial of service (invalid process state or TM Bad Thing exception, and system crash) or possibly have unspecified other impact by starting and suspending a transaction before an exec system call.
0
Attacker Value
Unknown
CVE-2016-1583
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
0
Attacker Value
Unknown
CVE-2014-9904
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
0
Attacker Value
Unknown
CVE-2016-4478
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
0
Attacker Value
Unknown
CVE-2016-2831
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
0
Attacker Value
Unknown
CVE-2016-2821
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
0
Attacker Value
Unknown
CVE-2016-2819
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
0
Attacker Value
Unknown
CVE-2016-2822
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
0
Attacker Value
Unknown
CVE-2016-2818
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
0