|
266211
|
7.5 |
HIGH
Network
|
oxide_project
|
oxide
|
A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.
|
CWE-20
Improper Input Validation
|
CVE-2016-1586
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266212
|
9.8 |
CRITICAL
Network
|
canonical
|
apparmor
|
In all versions of AppArmor mount rules are accidentally widened when compiled.
|
CWE-254
7PK - Security Features
|
CVE-2016-1585
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266213
|
5.3 |
MEDIUM
Network
|
unity8
|
unity8
|
In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.
|
CWE-399
Resource Management Errors
|
CVE-2016-1584
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266214
|
9.8 |
CRITICAL
Network
|
canonical
|
ubuntu_download_manager
|
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-1579
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266215
|
7.8 |
HIGH
Local
|
ubports
|
unity8
|
Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.
|
CWE-416
Use After Free
|
CVE-2016-1573
|
2024-11-21 11:46 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266216
|
7.8 |
HIGH
Local
|
debian
|
postgresql-common
|
The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, i…
|
CWE-59
Link Following
|
CVE-2016-1255
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266217
|
7.5 |
HIGH
Network
|
torproject opensuse_project debian fedoraproject opensuse
|
tor leap debian_linux fedora opensuse
|
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1254
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266218
|
9.8 |
CRITICAL
Network
|
debian
|
most
|
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell …
|
CWE-78
OS Command
|
CVE-2016-1253
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266219
|
5.9 |
MEDIUM
Network
|
debian canonical
|
advanced_package_tool ubuntu_linux
|
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 bef…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-1252
|
2024-11-21 11:46 |
2017-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266220
|
9.8 |
CRITICAL
Network
|
juniper
|
junos_space
|
A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices managed by Junos Space using cross site request forgery …
|
CWE-255 CWE-352 CWE-200
Credentials Management Origin Validation Error Information Exposure
|
CVE-2016-1265
|
2024-11-21 11:46 |
2017-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|