|
264551
|
7.8 |
HIGH
Local
|
imagemagick debian
|
imagemagick debian_linux
|
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular c…
|
CWE-787
Out-of-bounds Write
|
CVE-2016-8707
|
2024-11-21 11:59 |
2016-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264552
|
5.5 |
MEDIUM
Local
|
ffmpeg
|
ffmpeg
|
The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.
|
CWE-20
Improper Input Validation
|
CVE-2016-8595
|
2024-11-21 11:59 |
2016-12-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264553
|
8.8 |
HIGH
Local
|
joyent
|
smartos
|
An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when de…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-8733
|
2024-11-21 11:59 |
2016-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264554
|
7.8 |
HIGH
Local
|
linux canonical
|
linux_kernel ubuntu_linux
|
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capabilit…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2016-8655
|
2024-11-21 11:59 |
2016-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264555
|
7.5 |
HIGH
Network
|
apache
|
http_server
|
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to ca…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2016-8740
|
2024-11-21 11:59 |
2016-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264556
|
4.4 |
MEDIUM
Local
|
lenovo
|
thinkpad_10_ella_2_bios thinkpad_11e_beema_bios thinkpad_11e_braswell_bios thinkpad_11e_broadwell_bios thinkpad_11e_skylake_bios thinkpad_13e_bios thinkpad_e450_bios thinkpad_e45…
|
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mo…
|
CWE-284
Improper Access Control
|
CVE-2016-8222
|
2024-11-21 11:59 |
2016-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264557
|
4.4 |
MEDIUM
Local
|
lenovo
|
bios notebook_110_14ibr_bios notebook_110_15ibr_bios notebook_b70_80_bios notebook_e31_80_bios notebook_e40_80_bios notebook_e41_80_bios notebook_e51_80_bios notebook_g40_80_b…
|
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Managem…
|
CWE-310
Cryptographic Issues
|
CVE-2016-8224
|
2024-11-21 11:59 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264558
|
7.8 |
HIGH
Local
|
lenovo
|
system_interface_foundation
|
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with loca…
|
CWE-284
Improper Access Control
|
CVE-2016-8223
|
2024-11-21 11:59 |
2016-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264559
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memo…
|
CWE-20 CWE-399
Improper Input Validation Resource Management Errors
|
CVE-2016-8650
|
2024-11-21 11:59 |
2016-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264560
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a…
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-8646
|
2024-11-21 11:59 |
2016-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|