|
266311
|
6.0 |
MEDIUM
Local
|
qemu opensuse debian
|
qemu leap debian_linux
|
Memory leak in the v9fs_link function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via vectors involving a refer…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2016-9105
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266312
|
4.4 |
MEDIUM
Local
|
qemu debian opensuse
|
qemu debian_linux leap
|
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9104
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266313
|
6.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before wr…
|
CWE-200
Information Exposure
|
CVE-2016-9103
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266314
|
6.0 |
MEDIUM
Local
|
qemu debian
|
qemu debian_linux
|
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash)…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2016-9102
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266315
|
6.0 |
MEDIUM
Local
|
qemu opensuse debian
|
qemu leap debian_linux
|
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2016-9101
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266316
|
8.1 |
HIGH
Network
|
fedoraproject canonical djangoproject
|
fedora ubuntu_linux django
|
Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validat…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9014
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266317
|
9.8 |
CRITICAL
Network
|
djangoproject canonical fedoraproject
|
django ubuntu_linux fedora
|
Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it eas…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2016-9013
|
2024-11-21 12:00 |
2016-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266318
|
7.5 |
HIGH
Network
|
openbsd
|
openssh
|
The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE:…
|
CWE-399
Resource Management Errors
|
CVE-2016-8858
|
2024-11-21 12:00 |
2016-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266319
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by cal…
|
CWE-264 CWE-416
Permissions, Privileges, and Access Controls Use After Free
|
CVE-2016-9120
|
2024-11-21 12:00 |
2016-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266320
|
6.1 |
MEDIUM
Network
|
spip
|
spip
|
Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2016-9152
|
2024-11-21 12:00 |
2016-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|