|
265641
|
3.3 |
LOW
Local
|
nghttp2 fedoraproject
|
nghttp2 fedora
|
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-1544
|
2024-11-21 11:46 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265642
|
7.5 |
HIGH
Network
|
microfocus
|
identity_manager
|
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
|
CWE-200
Information Exposure
|
CVE-2016-1600
|
2024-11-21 11:46 |
2019-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265643
|
7.5 |
HIGH
Network
|
snapweb
|
snapweb
|
The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could …
|
CWE-284
Improper Access Control
|
CVE-2016-1587
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265644
|
7.5 |
HIGH
Network
|
oxide_project
|
oxide
|
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
|
CWE-20
Improper Input Validation
|
CVE-2016-1586
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265645
|
9.8 |
CRITICAL
Network
|
canonical
|
apparmor
|
In all versions of AppArmor mount rules are accidentally widened when compiled.
|
CWE-254
7PK - Security Features
|
CVE-2016-1585
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265646
|
5.3 |
MEDIUM
Network
|
unity8
|
unity8
|
In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.
|
CWE-399
Resource Management Errors
|
CVE-2016-1584
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265647
|
9.8 |
CRITICAL
Network
|
canonical
|
ubuntu_download_manager
|
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1579
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265648
|
7.8 |
HIGH
Local
|
ubports
|
unity8
|
Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.
|
CWE-416
Use After Free
|
CVE-2016-1573
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265649
|
7.8 |
HIGH
Local
|
debian
|
postgresql-common
|
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, i…
|
CWE-59
Link Following
|
CVE-2016-1255
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265650
|
7.5 |
HIGH
Network
|
torproject opensuse_project debian fedoraproject opensuse
|
tor leap debian_linux fedora opensuse
|
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1254
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|