|
267111
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by levera…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10191
|
2024-11-21 11:43 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267112
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a nega…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10190
|
2024-11-21 11:43 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267113
|
5.9 |
MEDIUM
Network
|
a10networks
|
advanced_core_operating_system
|
A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by le…
|
CWE-200
Information Exposure
|
CVE-2016-10213
|
2024-11-21 11:43 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267114
|
5.9 |
MEDIUM
Network
|
radware
|
alteon
|
Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-02…
|
CWE-200
Information Exposure
|
CVE-2016-10212
|
2024-11-21 11:43 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267115
|
7.8 |
HIGH
Local
|
linux google
|
linux_kernel android
|
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-10044
|
2024-11-21 11:43 |
2017-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267116
|
4.3 |
MEDIUM
Physics
|
linux
|
linux_kernel
|
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of servic…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-10208
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267117
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (sys…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-10154
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267118
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memor…
|
CWE-399
Resource Management Errors
|
CVE-2016-10153
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267119
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or poss…
|
CWE-264 CWE-416
Permissions, Privileges, and Access Controls Use After Free
|
CVE-2016-10150
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267120
|
9.8 |
CRITICAL
Network
|
sendquick
|
entera_sms_gateway_firmware avera_sms_gateway_firmware
|
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands.
|
CWE-77
Command Injection
|
CVE-2016-10098
|
2024-11-21 11:43 |
2017-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|