|
265881
|
7.5 |
HIGH
Network
|
novell canonical linux
|
suse_linux_enterprise_server suse_linux_enterprise_debuginfo suse_linux_enterprise_software_development_kit ubuntu_linux linux_kernel
|
The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack m…
|
CWE-200
Information Exposure
|
CVE-2016-4485
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265882
|
6.2 |
MEDIUM
Local
|
canonical linux novell fedoraproject
|
ubuntu_linux linux_kernel suse_linux_enterprise_module_for_public_cloud suse_linux_enterprise_server suse_linux_enterprise_live_patching suse_linux_enterprise_desktop suse_linux_ent…
|
The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from k…
|
CWE-200
Information Exposure
|
CVE-2016-4482
|
2024-11-21 11:52 |
2016-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265883
|
6.1 |
MEDIUM
Network
|
mediaelementjs wordpress
|
mediaelement.js wordpress
|
Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4567
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265884
|
6.1 |
MEDIUM
Network
|
wordpress plupload
|
wordpress plupload
|
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-O…
|
CWE-79
Cross-site Scripting
|
CVE-2016-4566
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265885
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject debian
|
php leap opensuse fedora debian_linux
|
The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a d…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4544
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265886
|
9.8 |
CRITICAL
Network
|
hp php fedoraproject opensuse
|
system_management_homepage php fedora leap
|
The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4543
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265887
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4542
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265888
|
9.8 |
CRITICAL
Network
|
fedoraproject php opensuse
|
fedora php leap
|
The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds…
|
NVD-CWE-Other
|
CVE-2016-4541
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265889
|
9.8 |
CRITICAL
Network
|
fedoraproject opensuse php
|
fedora leap php
|
The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bound…
|
NVD-CWE-Other
|
CVE-2016-4540
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265890
|
9.8 |
CRITICAL
Network
|
php opensuse fedoraproject
|
php leap fedora
|
The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segment…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-4539
|
2024-11-21 11:52 |
2016-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|