Show filters
117 Total Results
Displaying 81-90 of 117
Sort by:
Attacker Value
Unknown
CVE-2016-5244
Disclosure Date: June 27, 2016 (last updated November 25, 2024)
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message.
0
Attacker Value
Unknown
CVE-2016-4414
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.
0
Attacker Value
Unknown
CVE-2015-8869
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
0
Attacker Value
Unknown
CVE-2016-3720
Disclosure Date: June 10, 2016 (last updated November 25, 2024)
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2016-3096
Disclosure Date: June 03, 2016 (last updated November 25, 2024)
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
0
Attacker Value
Unknown
CVE-2016-4021
Disclosure Date: May 26, 2016 (last updated November 25, 2024)
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
0
Attacker Value
Unknown
CVE-2016-3959
Disclosure Date: May 23, 2016 (last updated November 08, 2023)
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
0
Attacker Value
Unknown
CVE-2016-4001
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
Buffer overflow in the stellaris_enet_receive function in hw/net/stellaris_enet.c in QEMU, when the Stellaris ethernet controller is configured to accept large packets, allows remote attackers to cause a denial of service (QEMU crash) via a large packet.
0
Attacker Value
Unknown
CVE-2016-4037
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.
0
Attacker Value
Unknown
CVE-2016-4482
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call.
0