|
265391
|
5.5 |
MEDIUM
Local
|
linux canonical debian redhat opensuse
|
linux_kernel ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_aus en…
|
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of…
|
CWE-200
Information Exposure
|
CVE-2016-4578
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265392
|
5.5 |
MEDIUM
Local
|
linux canonical novell
|
linux_kernel ubuntu_linux suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_ent…
|
The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from ke…
|
CWE-200
Information Exposure
|
CVE-2016-4569
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265393
|
7.8 |
HIGH
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or po…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-4565
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265394
|
7.0 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a …
|
NVD-CWE-Other
|
CVE-2016-4558
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265395
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or caus…
|
NVD-CWE-Other
|
CVE-2016-4557
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265396
|
3.3 |
LOW
Local
|
novell canonical linux
|
suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_enterprise_real_time_extension s…
|
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from …
|
CWE-200
Information Exposure
|
CVE-2016-4486
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265397
|
7.5 |
HIGH
Network
|
novell canonical linux
|
suse_linux_enterprise_server suse_linux_enterprise_debuginfo suse_linux_enterprise_software_development_kit ubuntu_linux linux_kernel
|
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack m…
|
CWE-200
Information Exposure
|
CVE-2016-4485
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265398
|
6.2 |
MEDIUM
Local
|
canonical linux novell fedoraproject
|
ubuntu_linux linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_ent…
|
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from k…
|
CWE-200
Information Exposure
|
CVE-2016-4482
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265399
|
6.1 |
MEDIUM
Network
|
mediaelementjs wordpress
|
mediaelement.js wordpress
|
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4567
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265400
|
6.1 |
MEDIUM
Network
|
wordpress plupload
|
wordpress plupload
|
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-O…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4566
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|