|
266251
|
6.0 |
MEDIUM
Local
|
qemu redhat debian
|
qemu virtualization debian_linux
|
The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging fail…
|
NVD-CWE-Other
|
CVE-2016-6835
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266252
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash…
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-6834
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266253
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance cr…
|
CWE-416
Use After Free
|
CVE-2016-6833
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266254
|
4.4 |
MEDIUM
Local
|
qemu
|
qemu
|
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero …
|
CWE-120
Classic Buffer Overflow
|
CVE-2016-6490
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266255
|
9.8 |
CRITICAL
Network
|
jfrog
|
artifactory
|
JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.
|
CWE-20
Improper Input Validation
|
CVE-2016-6501
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266256
|
9.8 |
CRITICAL
Network
|
atlassian
|
crowd
|
The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka …
|
CWE-20
Improper Input Validation
|
CVE-2016-6496
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266257
|
9.8 |
CRITICAL
Network
|
barclamp-trove_project crowbar-openstack_project
|
barclamp-trove crowbar-openstack
|
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, whic…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-6829
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266258
|
6.1 |
MEDIUM
Network
|
dotclear
|
dotclear
|
Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2016-6523
|
2024-11-21 11:56 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266259
|
8.8 |
HIGH
Network
|
google
|
android
|
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is…
|
CWE-74
Injection
|
CVE-2016-6754
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266260
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious applic…
|
CWE-200
Information Exposure
|
CVE-2016-6753
|
2024-11-21 11:56 |
2016-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|