|
266421
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a set…
|
CWE-285
Improper Authorization
|
CVE-2016-7097
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266422
|
6.2 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain tim…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7042
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266423
|
7.5 |
HIGH
Network
|
oracle linux
|
vm_server linux linux_kernel
|
The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GR…
|
CWE-399
Resource Management Errors
|
CVE-2016-7039
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266424
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7194
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266425
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7190
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266426
|
7.3 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7211
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266427
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7189
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266428
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10
|
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted applicatio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7188
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266429
|
7.8 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7185
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266430
|
9.8 |
CRITICAL
Network
|
microsoft
|
word_viewer live_meeting windows_server_2012 lync office windows_10 windows_8.1 windows_server_2008 skype_for_business windows_7 windows_rt_8.1 windows_vista
|
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607…
|
CWE-20
Improper Input Validation
|
CVE-2016-7182
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|