|
265061
|
8.2 |
HIGH
Local
|
xen
|
xen
|
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7093
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265062
|
8.2 |
HIGH
Local
|
xen
|
xen
|
The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-7092
|
2024-11-21 11:57 |
2016-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265063
|
5.4 |
MEDIUM
Network
|
nextcloud owncloud
|
nextcloud_server owncloud
|
Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2016-7419
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265064
|
7.5 |
HIGH
Network
|
php
|
php
|
The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service (invalid pointer access and out-of-bounds read) o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7418
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265065
|
9.8 |
CRITICAL
Network
|
php
|
php
|
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial …
|
CWE-20
Improper Input Validation
|
CVE-2016-7417
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265066
|
7.5 |
HIGH
Network
|
php
|
php
|
ext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to the Locale class in the ICU library, which allows remote atta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7416
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265067
|
9.8 |
CRITICAL
Network
|
icu-project
|
international_components_for_unicode
|
Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remote attackers to cause a denial of service (applicat…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7415
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265068
|
9.8 |
CRITICAL
Network
|
php
|
php
|
The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enough, which allows remote attackers to cause a denial…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7414
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265069
|
9.8 |
CRITICAL
Network
|
php
|
php
|
Use-after-free vulnerability in the wddx_stack_destroy function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial of service or possibly have uns…
|
CWE-416
Use After Free
|
CVE-2016-7413
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265070
|
8.1 |
HIGH
Network
|
php
|
php
|
ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of servi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7412
|
2024-11-21 11:57 |
2016-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|