Show filters
344 Total Results
Displaying 81-90 of 344
Sort by:
Attacker Value
Unknown
CVE-2016-4913
Disclosure Date: May 23, 2016 (last updated November 25, 2024)
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem.
0
Attacker Value
Unknown
CVE-2015-8866
Disclosure Date: May 22, 2016 (last updated November 08, 2023)
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.
0
Attacker Value
Unknown
CVE-2016-3718
Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
0
Attacker Value
Unknown
CVE-2016-3715
Disclosure Date: May 05, 2016 (last updated July 25, 2024)
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
0
Attacker Value
Unknown
CVE-2016-3137
Disclosure Date: May 02, 2016 (last updated November 08, 2023)
drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and cypress_open functions.
0
Attacker Value
Unknown
CVE-2016-3951
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.
0
Attacker Value
Unknown
CVE-2016-3138
Disclosure Date: May 02, 2016 (last updated November 08, 2023)
The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor.
0
Attacker Value
Unknown
CVE-2016-2187
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
0
Attacker Value
Unknown
CVE-2016-3689
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface.
0
Attacker Value
Unknown
CVE-2016-2186
Disclosure Date: May 02, 2016 (last updated November 25, 2024)
The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
0