|
267771
|
9.8 |
CRITICAL
Network
|
graphicsmagick suse oracle opensuse canonical debian imagemagick
|
graphicsmagick studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo solaris linux leap opensuse ubuntu_linux debian_linux linux_enterprise_…
|
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
|
NVD-CWE-noinfo
|
CVE-2016-5118
|
2024-11-21 11:53 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267772
|
9.8 |
CRITICAL
Network
|
debian videolan
|
debian_linux vlc_media_player
|
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5108
|
2024-11-21 11:53 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267773
|
5.6 |
MEDIUM
Local
|
xen
|
xen
|
The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS …
|
NVD-CWE-Other
|
CVE-2016-5242
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267774
|
4.7 |
MEDIUM
Local
|
xen
|
xen
|
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the…
|
CWE-284
Improper Access Control
|
CVE-2016-4963
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267775
|
6.7 |
MEDIUM
Local
|
oracle xen
|
vm_server xen
|
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4962
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267776
|
6.1 |
MEDIUM
Network
|
markdown_on_saved_improved_project
|
markdown_on_saved_improved
|
Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4812
|
2024-11-21 11:53 |
2016-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267777
|
6.2 |
MEDIUM
Local
|
dosfstools_project opensuse canonical
|
dosfstools leap opensuse ubuntu_linux
|
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4804
|
2024-11-21 11:53 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267778
|
7.8 |
HIGH
Local
|
qemu canonical oracle debian redhat
|
qemu ubuntu_linux linux debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server o…
|
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code vi…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5126
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267779
|
6.1 |
MEDIUM
Network
|
citrix
|
netscaler_gateway_11.0_firmware
|
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4945
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267780
|
7.5 |
HIGH
Network
|
citrix
|
xenapp xendesktop
|
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Con…
|
CWE-284
Improper Access Control
|
CVE-2016-4810
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|