|
265121
|
7.0 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a …
|
NVD-CWE-Other
|
CVE-2016-4558
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265122
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or caus…
|
NVD-CWE-Other
|
CVE-2016-4557
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265123
|
3.3 |
LOW
Local
|
novell canonical linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_time_extension s…
|
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from …
|
CWE-200
Information Exposure
|
CVE-2016-4486
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265124
|
7.5 |
HIGH
Network
|
novell canonical linux
|
suse_linux_enterprise_server suse_linux_enterprise_debuginfo suse_linux_enterprise_software_development_kit ubuntu_linux linux_kernel
|
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack m…
|
CWE-200
Information Exposure
|
CVE-2016-4485
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265125
|
6.2 |
MEDIUM
Local
|
canonical linux novell fedoraproject
|
ubuntu_linux linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_ent…
|
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from k…
|
CWE-200
Information Exposure
|
CVE-2016-4482
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265126
|
6.1 |
MEDIUM
Network
|
mediaelementjs wordpress
|
mediaelement.js wordpress
|
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4567
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265127
|
6.1 |
MEDIUM
Network
|
wordpress plupload
|
wordpress plupload
|
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-O…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4566
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265128
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject debian
|
php leap opensuse fedora debian_linux
|
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a d…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4544
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265129
|
9.8 |
CRITICAL
Network
|
hp php fedoraproject opensuse
|
system_management_homepage php fedora leap
|
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4543
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265130
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4542
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|