|
266141
|
7.8 |
HIGH
Local
|
linux google
|
linux_kernel android
|
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10044
|
2024-11-21 11:43 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266142
|
4.3 |
MEDIUM
Physics
|
linux
|
linux_kernel
|
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of servic…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10208
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266143
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (sys…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10154
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266144
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memor…
|
CWE-399
Resource Management Errors
|
CVE-2016-10153
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266145
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or poss…
|
CWE-264 CWE-416
Permissions, Privileges, and Access Controls Use After Free
|
CVE-2016-10150
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266146
|
9.8 |
CRITICAL
Network
|
sendquick
|
entera_sms_gateway_firmware avera_sms_gateway_firmware
|
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
|
CWE-77
Command Injection
|
CVE-2016-10098
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266147
|
7.1 |
HIGH
Local
|
littlecms debian canonical opensuse redhat netapp
|
little_cms_color_engine debian_linux ubuntu_linux leap enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_tus enterprise_lin…
|
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which …
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10165
|
2024-11-21 11:43 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266148
|
7.5 |
HIGH
Network
|
sap
|
saplpd
|
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.
|
CWE-20
Improper Input Validation
|
CVE-2016-10079
|
2024-11-21 11:43 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266149
|
7.5 |
HIGH
Network
|
minitar
|
archive-tar-minitar minitar
|
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
|
CWE-22
Path Traversal
|
CVE-2016-10173
|
2024-11-21 11:43 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266150
|
9.8 |
CRITICAL
Network
|
x.org
|
libxpm
|
Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to cause a denial of service (out-of-bounds write) or e…
|
CWE-119 CWE-787 CWE-190
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2016-10164
|
2024-11-21 11:43 |
2017-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|