|
265231
|
5.3 |
MEDIUM
Network
|
libimobiledevice canonical opensuse
|
libimobiledevice libusbmuxd ubuntu_linux leap opensuse
|
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connect…
|
CWE-284
Improper Access Control
|
CVE-2016-5104
|
2024-11-21 11:53 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265232
|
4.3 |
MEDIUM
Network
|
keystone
|
openstack_identity
|
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrict…
|
CWE-284
Improper Access Control
|
CVE-2016-4911
|
2024-11-21 11:53 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265233
|
3.7 |
LOW
Network
|
huawei
|
mate_8_firmware
|
Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base statio…
|
CWE-200
Information Exposure
|
CVE-2016-5233
|
2024-11-21 11:53 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265234
|
9.8 |
CRITICAL
Network
|
graphicsmagick suse oracle opensuse canonical debian imagemagick
|
graphicsmagick studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo solaris linux leap opensuse ubuntu_linux debian_linux linux_enterprise_…
|
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
|
NVD-CWE-noinfo
|
CVE-2016-5118
|
2024-11-21 11:53 |
2016-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265235
|
9.8 |
CRITICAL
Network
|
debian videolan
|
debian_linux vlc_media_player
|
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute ar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5108
|
2024-11-21 11:53 |
2016-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265236
|
5.6 |
MEDIUM
Local
|
xen
|
xen
|
The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (NULL pointer dereference and host OS …
|
NVD-CWE-Other
|
CVE-2016-5242
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265237
|
4.7 |
MEDIUM
Local
|
xen
|
xen
|
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the…
|
CWE-284
Improper Access Control
|
CVE-2016-4963
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265238
|
6.7 |
MEDIUM
Local
|
oracle xen
|
vm_server xen
|
The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or management facility confusion) or gain host OS privileges…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4962
|
2024-11-21 11:53 |
2016-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265239
|
6.1 |
MEDIUM
Network
|
markdown_on_saved_improved_project
|
markdown_on_saved_improved
|
Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-4812
|
2024-11-21 11:53 |
2016-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265240
|
6.2 |
MEDIUM
Local
|
dosfstools_project opensuse canonical
|
dosfstools leap opensuse ubuntu_linux
|
The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4804
|
2024-11-21 11:53 |
2016-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|