|
266521
|
7.8 |
HIGH
Local
|
freedesktop redhat
|
polkit enterprise_linux
|
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2016-2568
|
2024-11-21 11:48 |
2017-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266522
|
4.3 |
MEDIUM
Network
|
ibm
|
rational_collaborative_lifecycle_management
|
An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user.
|
CWE-200
Information Exposure
|
CVE-2016-2866
|
2024-11-21 11:48 |
2017-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266523
|
9.8 |
CRITICAL
Network
|
sensiolabs
|
symfony
|
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
|
CWE-287
Improper Authentication
|
CVE-2016-2403
|
2024-11-21 11:48 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266524
|
6.5 |
MEDIUM
Local
|
gnu
|
coreutils
|
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
|
CWE-20
Improper Input Validation
|
CVE-2016-2781
|
2024-11-21 11:48 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266525
|
7.8 |
HIGH
Local
|
kernel
|
util-linux
|
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2779
|
2024-11-21 11:48 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266526
|
8.8 |
HIGH
Network
|
atutor
|
atutor
|
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files an…
|
CWE-352
Origin Validation Error
|
CVE-2016-2539
|
2024-11-21 11:48 |
2017-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266527
|
5.5 |
MEDIUM
Local
|
graphicsmagick debian suse opensuse
|
graphicsmagick debian_linux studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo leap opensuse
|
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartEle…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-2318
|
2024-11-21 11:48 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266528
|
5.5 |
MEDIUM
Local
|
graphicsmagick debian suse opensuse
|
graphicsmagick debian_linux studio_onsite linux_enterprise_software_development_kit linux_enterprise_debuginfo leap opensuse
|
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) G…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2317
|
2024-11-21 11:48 |
2017-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266529
|
5.9 |
MEDIUM
Network
|
squareup
|
okhttp3 okhttp
|
OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-2402
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266530
|
7.8 |
HIGH
Local
|
libquicktime
|
libquicktime
|
Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted h…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2399
|
2024-11-21 11:48 |
2017-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|