|
265961
|
5.9 |
MEDIUM
Network
|
inspircd debian
|
inspircd debian_linux
|
The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7142
|
2024-11-21 11:57 |
2016-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265962
|
8.1 |
HIGH
Network
|
gnu
|
wget
|
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP …
|
CWE-362
Race Condition
|
CVE-2016-7098
|
2024-11-21 11:57 |
2016-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265963
|
5.5 |
MEDIUM
Local
|
redhat libarchive oracle
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_…
|
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip…
|
CWE-399
Resource Management Errors
|
CVE-2016-7166
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265964
|
7.8 |
HIGH
Local
|
uclouvain debian fedoraproject redhat
|
openjpeg debian_linux fedora enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus enterprise_l…
|
Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-7163
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265965
|
6.7 |
MEDIUM
Local
|
xen
|
xen
|
Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain s…
|
CWE-416
Use After Free
|
CVE-2016-7154
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265966
|
8.1 |
HIGH
Network
|
debian charybdis_project
|
debian_linux charybdis
|
The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE …
|
CWE-285
Improper Authorization
|
CVE-2016-7143
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265967
|
4.1 |
MEDIUM
Local
|
xen
|
xen
|
Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7094
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265968
|
8.2 |
HIGH
Local
|
xen
|
xen
|
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7093
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265969
|
8.2 |
HIGH
Local
|
xen
|
xen
|
The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7092
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265970
|
5.4 |
MEDIUM
Network
|
nextcloud owncloud
|
nextcloud_server owncloud
|
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2016-7419
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|