|
264681
|
3.3 |
LOW
Local
|
sap
|
netweaver
|
SAP Netweaver 7.40 improperly logs (1) DUI and (2) DUJ events in the SAP Security Audit Log as non-critical, which might allow local users to hide rejected attempts to execute RFC function callbacks …
|
NVD-CWE-Other
|
CVE-2016-7437
|
2024-11-21 11:58 |
2016-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264682
|
2.5 |
LOW
Local
|
siemens
|
simatic_step_7
|
Siemens SIMATIC STEP 7 (TIA Portal) before 14 uses an improper format for managing TIA project files during version updates, which makes it easier for local users to obtain sensitive configuration in…
|
CWE-200
Information Exposure
|
CVE-2016-7960
|
2024-11-21 11:58 |
2016-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264683
|
4.7 |
MEDIUM
Local
|
siemens
|
simatic_step_7
|
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to…
|
CWE-254
7PK - Security Features
|
CVE-2016-7959
|
2024-11-21 11:58 |
2016-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264684
|
5.5 |
MEDIUM
Local
|
systemd_project novell redhat
|
systemd suse_linux_enterprise_server suse_linux_enterprise_desktop suse_linux_enterprise_server_for_sap suse_linux_enterprise_software_development_kit enterprise_linux_desktop enter…
|
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be r…
|
CWE-20
Improper Input Validation
|
CVE-2016-7796
|
2024-11-21 11:58 |
2016-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264685
|
7.8 |
HIGH
Local
|
intel
|
solid-state_drive_toolbox
|
The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-8101
|
2024-11-21 11:58 |
2016-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264686
|
5.5 |
MEDIUM
Local
|
intel
|
integrated_performance_primitives
|
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.
|
CWE-200
Information Exposure
|
CVE-2016-8100
|
2024-11-21 11:58 |
2016-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264687
|
6.3 |
MEDIUM
Local
|
xen
|
xen
|
Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks o…
|
CWE-362
Race Condition
|
CVE-2016-7777
|
2024-11-21 11:58 |
2016-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264688
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1)…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2016-7909
|
2024-11-21 11:58 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264689
|
4.4 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators t…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2016-7908
|
2024-11-21 11:58 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264690
|
4.4 |
MEDIUM
Local
|
qemu
|
qemu
|
The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators t…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2016-7907
|
2024-11-21 11:58 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|