|
265311
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of servi…
|
CWE-189 NVD-CWE-Other
Numeric Errors
|
CVE-2016-3135
|
2024-11-21 11:49 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265312
|
4.6 |
MEDIUM
Physics
|
novell linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_real_time_extension suse_linux_enterprise_desktop s…
|
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system cr…
|
NVD-CWE-Other
|
CVE-2016-3139
|
2024-11-21 11:49 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265313
|
8.4 |
HIGH
Local
|
novell linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_time_extension s…
|
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3134
|
2024-11-21 11:49 |
2016-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265314
|
9.8 |
CRITICAL
Network
|
apache
|
struts
|
XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.
|
CWE-20
Improper Input Validation
|
CVE-2016-3082
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265315
|
8.1 |
HIGH
Network
|
apache oracle
|
struts siebel_e-billing
|
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to …
|
CWE-77
Command Injection
|
CVE-2016-3081
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265316
|
9.8 |
CRITICAL
Network
|
libgd debian fedoraproject canonical opensuse php
|
libgd debian_linux fedora ubuntu_linux opensuse php
|
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed g…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2016-3074
|
2024-11-21 11:49 |
2016-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265317
|
6.1 |
MEDIUM
Network
|
blackberry
|
enterprise_server
|
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted …
|
CWE-79
Cross-site Scripting
|
CVE-2016-3126
|
2024-11-21 11:49 |
2016-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265318
|
4.6 |
MEDIUM
Physics
|
lexmark
|
printer_firmware
|
Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows ph…
|
CWE-200
Information Exposure
|
CVE-2016-3145
|
2024-11-21 11:49 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265319
|
7.5 |
HIGH
Network
|
opensuse cairographics
|
opensuse cairo
|
The fill_xrgb32_lerp_opaque_spans function in cairo-image-compositor.c in cairo before 1.14.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a neg…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-3190
|
2024-11-21 11:49 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265320
|
6.4 |
MEDIUM
Network
|
oracle
|
agile_product_lifecycle_management_framework
|
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and in…
|
NVD-CWE-noinfo
|
CVE-2016-3431
|
2024-11-21 11:49 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|