|
266991
|
5.5 |
MEDIUM
Local
|
openssl oracle suse nodejs debian canonical
|
openssl solaris linux linux_enterprise node.js debian_linux ubuntu_linux
|
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pr…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2016-2178
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266992
|
9.8 |
CRITICAL
Network
|
hp openssl oracle
|
icewall_sso icewall_mcrp icewall_sso_agent_option openssl solaris linux
|
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-2177
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266993
|
4.3 |
MEDIUM
Network
|
apple
|
safari iphone_os
|
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a…
|
CWE-200
Information Exposure
|
CVE-2016-1864
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266994
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-1862
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266995
|
7.8 |
HIGH
Local
|
apple
|
mac_os_x
|
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted ap…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1861
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266996
|
3.3 |
LOW
Local
|
apple
|
mac_os_x
|
Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2016-1860
|
2024-11-21 11:47 |
2016-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266997
|
7.2 |
HIGH
Network
|
apache
|
ranger
|
SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/…
|
CWE-89
SQL Injection
|
CVE-2016-2174
|
2024-11-21 11:47 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266998
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attacker…
|
CWE-269
Improper Privilege Management
|
CVE-2016-2066
|
2024-11-21 11:47 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266999
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers…
|
CWE-269
Improper Privilege Management
|
CVE-2016-2061
|
2024-11-21 11:47 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267000
|
7.1 |
HIGH
Local
|
redhat opensuse debian spice_project
|
enterprise_linux enterprise_linux_desktop enterprise_linux_hpc_node_eus enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus enterprise_linux_workstation<…
|
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
|
CWE-284
Improper Access Control
|
CVE-2016-2150
|
2024-11-21 11:47 |
2016-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|