|
266081
|
9.8 |
CRITICAL
Network
|
sybase
|
adaptive_server_enterprise
|
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7402
|
2024-11-21 11:57 |
2016-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266082
|
7.5 |
HIGH
Network
|
samsung
|
samsung_mobile
|
A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-7160
|
2024-11-21 11:57 |
2016-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266083
|
9.8 |
CRITICAL
Network
|
exponentcms
|
exponent_cms
|
Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2016-7095
|
2024-11-21 11:57 |
2016-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266084
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
The arcmsr_iop_message_xfer function in drivers/scsi/arcmsr/arcmsr_hba.c in the Linux kernel through 4.8.2 does not restrict a certain length field, which allows local users to gain privileges or cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7425
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266085
|
4.4 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a set…
|
CWE-285
Improper Authorization
|
CVE-2016-7097
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266086
|
6.2 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The proc_keys_show function in security/keys/proc.c in the Linux kernel through 4.8.2, when the GNU Compiler Collection (gcc) stack protector is enabled, uses an incorrect buffer size for certain tim…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7042
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266087
|
7.5 |
HIGH
Network
|
oracle linux
|
vm_server linux linux_kernel
|
The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GR…
|
CWE-399
Resource Management Errors
|
CVE-2016-7039
|
2024-11-21 11:57 |
2016-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266088
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7194
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266089
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7190
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266090
|
7.3 |
HIGH
Local
|
microsoft
|
windows_rt_8.1 windows_server_2012 windows_7 windows_10 windows_8.1 windows_server_2008 windows_vista
|
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7211
|
2024-11-21 11:57 |
2016-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|