|
266421
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue i…
|
CWE-284
Improper Access Control
|
CVE-2016-7054
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266422
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-7053
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266423
|
5.9 |
MEDIUM
Network
|
openssl nodejs
|
openssl node.js
|
There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bi…
|
NVD-CWE-noinfo
|
CVE-2016-7055
|
2024-11-21 11:57 |
2017-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266424
|
7.8 |
HIGH
Local
|
nvidia
|
shield_tablet_firmware shield_tablet_tk1_firmware shield_tv_firmware video_driver
|
Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6915
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266425
|
7.8 |
HIGH
Local
|
nvidia
|
shield_tablet_firmware shield_tablet_tk1_firmware shield_tv_firmware video_driver
|
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-6917
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266426
|
7.8 |
HIGH
Local
|
nvidia
|
shield_tablet_firmware shield_tablet_tk1_firmware shield_tv_firmware video_driver
|
Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5 allows local users to cause a denia…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-6916
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266427
|
9.9 |
CRITICAL
Network
|
lshell_project
|
lshell
|
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6903
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266428
|
9.9 |
CRITICAL
Network
|
lshell_project
|
lshell
|
lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-6902
|
2024-11-21 11:57 |
2017-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266429
|
4.6 |
MEDIUM
Physics
|
redhat
|
quickstart_cloud_installer
|
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the d…
|
CWE-200
Information Exposure
|
CVE-2016-7060
|
2024-11-21 11:57 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266430
|
8.6 |
HIGH
Network
|
fasterxml
|
jackson-dataformat-xml
|
XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via ve…
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2016-7051
|
2024-11-21 11:57 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|