|
257011
|
8.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, cause a denial of service (host crash), or execute …
|
CWE-20
Improper Input Validation
|
CVE-2016-9383
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257012
|
7.8 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a gue…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9382
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257013
|
7.5 |
HIGH
Local
|
qemu citrix
|
qemu xenserver
|
Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.
|
CWE-362
Race Condition
|
CVE-2016-9381
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257014
|
7.5 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in…
|
CWE-20
Improper Input Validation
|
CVE-2016-9380
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257015
|
7.9 |
HIGH
Local
|
xen citrix
|
xen xenserver
|
The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes…
|
CWE-20
Improper Input Validation
|
CVE-2016-9379
|
2024-11-21 12:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257016
|
7.8 |
HIGH
Local
|
broadcom ca
|
ca_workload_automation_ae client_automation systemedge systems_performance_for_infrastructure_managers universal_job_management_agent virtual_assurance_for_infrastructure_managers
|
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Unive…
|
CWE-20
Improper Input Validation
|
CVE-2016-9795
|
2024-11-21 12:01 |
2017-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257017
|
6.7 |
MEDIUM
Local
|
emc
|
isilon_onefs
|
EMC Isilon OneFS 8.0.0.0, EMC Isilon OneFS 7.2.1.0 - 7.2.1.2, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, and EMC Isilon OneFS 7.1.0.x is affected by an LDAP injection vulnerabilit…
|
CWE-90
LDAP Injection
|
CVE-2016-9870
|
2024-11-21 12:01 |
2017-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257018
|
6.5 |
MEDIUM
Network
|
opensuse_project opensuse tats
|
leap w3m
|
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.
|
CWE-20
Improper Input Validation
|
CVE-2016-9436
|
2024-11-21 12:01 |
2017-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257019
|
6.5 |
MEDIUM
Network
|
opensuse_project opensuse tats
|
leap w3m
|
The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd…
|
CWE-20
Improper Input Validation
|
CVE-2016-9435
|
2024-11-21 12:01 |
2017-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257020
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a…
|
CWE-19
Data Processing Errors
|
CVE-2016-9650
|
2024-11-21 12:01 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|