|
257041
|
8.8 |
HIGH
Local
|
emc
|
scaleio
|
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI driver and may achieve code execution to escalate …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9867
|
2024-11-21 12:01 |
2017-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257042
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain pri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9754
|
2024-11-21 12:01 |
2017-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257043
|
6.5 |
MEDIUM
Local
|
qemu
|
qemu
|
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9846
|
2024-11-21 12:01 |
2016-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257044
|
6.5 |
MEDIUM
Local
|
qemu
|
qemu
|
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A …
|
CWE-200
Information Exposure
|
CVE-2016-9845
|
2024-11-21 12:01 |
2016-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257045
|
5.5 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A pri…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2016-9776
|
2024-11-21 12:01 |
2016-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257046
|
5.4 |
MEDIUM
Network
|
dotclear
|
dotclear
|
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletit…
|
CWE-79
Cross-site Scripting
|
CVE-2016-9891
|
2024-11-21 12:01 |
2016-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257047
|
7.5 |
HIGH
Network
|
pivotal_software vmware
|
spring_framework
|
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result expose…
|
CWE-22
Path Traversal
|
CVE-2016-9878
|
2024-11-21 12:01 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257048
|
9.8 |
CRITICAL
Network
|
pivotal_software vmware
|
rabbitmq
|
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport…
|
CWE-284
Improper Access Control
|
CVE-2016-9877
|
2024-11-21 12:01 |
2016-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257049
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified oth…
|
CWE-362 CWE-415
Race Condition Double Free
|
CVE-2016-9806
|
2024-11-21 12:01 |
2016-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257050
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the snd_pcm_period_elapsed function in sound/core/pcm_lib.c in the ALSA subsystem in the Linux kernel before 4.7 allows local users to cause a denial of service (use-after-free) or …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2016-9794
|
2024-11-21 12:01 |
2016-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|