|
265241
|
7.8 |
HIGH
Local
|
qemu canonical oracle debian redhat
|
qemu ubuntu_linux linux debian_linux enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server o…
|
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code vi…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-5126
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265242
|
6.1 |
MEDIUM
Network
|
citrix
|
netscaler_gateway_11.0_firmware
|
Cross-site scripting (XSS) vulnerability in vpn/js/gateway_login_form_view.js in Citrix NetScaler Gateway 11.0 before Build 66.11 allows remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4945
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265243
|
7.5 |
HIGH
Network
|
citrix
|
xenapp xendesktop
|
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Con…
|
CWE-284
Improper Access Control
|
CVE-2016-4810
|
2024-11-21 11:53 |
2016-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265244
|
7.8 |
HIGH
Local
|
linux canonical oracle
|
linux_kernel ubuntu_linux linux
|
The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference a…
|
NVD-CWE-Other
|
CVE-2016-4951
|
2024-11-21 11:53 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265245
|
7.8 |
HIGH
Local
|
canonical linux oracle novell
|
ubuntu_linux linux_kernel linux suse_linux_enterprise_server suse_linux_enterprise_debuginfo suse_linux_enterprise_software_development_kit
|
The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensit…
|
CWE-200
Information Exposure
|
CVE-2016-4913
|
2024-11-21 11:53 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265246
|
7.8 |
HIGH
Local
|
novell redhat canonical linux oracle
|
suse_linux_enterprise_desktop suse_linux_enterprise_workstation_extension suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server opensuse_leap suse_linux_enterprise…
|
Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or pos…
|
CWE-416
Use After Free
|
CVE-2016-4805
|
2024-11-21 11:53 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265247
|
7.5 |
HIGH
Network
|
zulip
|
zulip
|
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.
|
NVD-CWE-noinfo
|
CVE-2016-4427
|
2024-11-21 11:52 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265248
|
4.3 |
MEDIUM
Network
|
zulip
|
zulip
|
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.
|
NVD-CWE-noinfo
|
CVE-2016-4426
|
2024-11-21 11:52 |
2022-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265249
|
9.8 |
CRITICAL
Network
|
haxx
|
curl
|
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass …
|
NVD-CWE-noinfo
|
CVE-2016-4606
|
2024-11-21 11:52 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265250
|
7.5 |
HIGH
Network
|
apple
|
mac_os_x safari
|
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2016-4676
|
2024-11-21 11:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|