Show filters
456 Total Results
Displaying 71-80 of 456
Sort by:
Attacker Value
Unknown

CVE-2016-1583

Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.
Attacker Value
Unknown

CVE-2014-9904

Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
Attacker Value
Unknown

CVE-2016-4478

Disclosure Date: June 13, 2016 (last updated November 25, 2024)
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
0
Attacker Value
Unknown

CVE-2016-2831

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
0
Attacker Value
Unknown

CVE-2016-2821

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
0
Attacker Value
Unknown

CVE-2016-2819

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
0
Attacker Value
Unknown

CVE-2016-2822

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
0
Attacker Value
Unknown

CVE-2016-2818

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown

CVE-2016-2828

Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
0
Attacker Value
Unknown

CVE-2016-5118

Disclosure Date: June 10, 2016 (last updated November 20, 2024)
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.