|
266201
|
6.0 |
MEDIUM
Local
|
qemu opensuse debian
|
qemu leap debian_linux
|
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2016-9101
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266202
|
8.1 |
HIGH
Network
|
fedoraproject canonical djangoproject
|
fedora ubuntu_linux django
|
Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validat…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9014
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266203
|
9.8 |
CRITICAL
Network
|
djangoproject canonical fedoraproject
|
django ubuntu_linux fedora
|
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it eas…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-9013
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266204
|
7.5 |
HIGH
Network
|
openbsd
|
openssh
|
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE:…
|
CWE-399
Resource Management Errors
|
CVE-2016-8858
|
2024-11-21 12:00 |
2016-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266205
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by cal…
|
CWE-264 CWE-416
Permissions, Privileges, and Access Controls Use After Free
|
CVE-2016-9120
|
2024-11-21 12:00 |
2016-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266206
|
6.1 |
MEDIUM
Network
|
spip
|
spip
|
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9152
|
2024-11-21 12:00 |
2016-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266207
|
9.8 |
CRITICAL
Network
|
siemens
|
sicam_pas\/pqs
|
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by …
|
CWE-20 CWE-284
Improper Input Validation Improper Access Control
|
CVE-2016-9157
|
2024-11-21 12:00 |
2016-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266208
|
7.3 |
HIGH
Network
|
siemens
|
sicam_pas\/pqs
|
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted pa…
|
CWE-20 CWE-284
Improper Input Validation Improper Access Control
|
CVE-2016-9156
|
2024-11-21 12:00 |
2016-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266209
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial o…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-9313
|
2024-11-21 12:00 |
2016-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266210
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2016-9191
|
2024-11-21 12:00 |
2016-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|