Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 54 399

Количество 54 399

redhat логотип

CVE-2016-6288

почти 11 лет назад

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2016-6263

больше 10 лет назад

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2016-6262

больше 10 лет назад

idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2016-6261

около 10 лет назад

The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2016-6259

около 10 лет назад

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

CVSS3: 6.3
EPSS: Низкий
redhat логотип

CVE-2016-6258

около 10 лет назад

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

CVSS3: 8.5
EPSS: Низкий
redhat логотип

CVE-2016-6254

около 10 лет назад

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2016-6252

около 10 лет назад

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2016-6251

около 10 лет назад

No description is available for this CVE.

CVSS3: 4.4
EPSS: Низкий
redhat логотип

CVE-2016-6250

около 10 лет назад

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

CVSS3: 7.9
EPSS: Низкий
redhat логотип

CVE-2016-6224

около 10 лет назад

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2016-6223

около 10 лет назад

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2016-6214

около 10 лет назад

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

CVSS3: 4
EPSS: Низкий
redhat логотип

CVE-2016-6213

около 10 лет назад

fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.

CVSS3: 4.7
EPSS: Низкий
redhat логотип

CVE-2016-6210

около 10 лет назад

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

CVSS3: 5.3
EPSS: Высокий
redhat логотип

CVE-2016-6209

около 10 лет назад

Cross-site scripting (XSS) vulnerability in Nagios.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2016-6207

около 10 лет назад

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.2
EPSS: Низкий
redhat логотип

CVE-2016-6199

около 10 лет назад

ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2016-6198

около 10 лет назад

The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2016-6197

около 10 лет назад

fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2016-6288

The php_url_parse_ex function in ext/standard/url.c in PHP before 5.5.38 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via vectors involving the smart_str data type.

CVSS3: 6.2
5%
Низкий
почти 11 лет назад
redhat логотип
CVE-2016-6263

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.

CVSS3: 3.7
4%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-6262

idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.

CVSS3: 3.7
7%
Низкий
больше 10 лет назад
redhat логотип
CVE-2016-6261

The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.

CVSS3: 3.7
4%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6259

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

CVSS3: 6.3
1%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6258

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

CVSS3: 8.5
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6254

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

CVSS3: 8.6
6%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6252

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

CVSS3: 5.3
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6251

No description is available for this CVE.

CVSS3: 4.4
около 10 лет назад
redhat логотип
CVE-2016-6250

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

CVSS3: 7.9
6%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6224

ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-8946.

CVSS3: 4.7
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6223

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (crash) or possibly obtain sensitive information via a negative index in a file-content buffer.

CVSS3: 6.5
3%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6214

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

CVSS3: 4
3%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6213

fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.

CVSS3: 4.7
0%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6210

sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

CVSS3: 5.3
89%
Высокий
около 10 лет назад
redhat логотип
CVE-2016-6209

Cross-site scripting (XSS) vulnerability in Nagios.

CVSS2: 4.3
2%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6207

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds memory write or memory consumption) via unspecified vectors.

CVSS3: 6.2
6%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6199

ObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.

CVSS3: 8.1
5%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6198

The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei.c and fs/open.c.

CVSS3: 5.5
1%
Низкий
около 10 лет назад
redhat логотип
CVE-2016-6197

fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceeding with unlink and rename system-call processing, which allows local users to cause a denial of service (system crash) via a rename system call that specifies a self-hardlink.

CVSS3: 5.5
0%
Низкий
около 10 лет назад

Уязвимостей на страницу