Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2016-9276

больше 9 лет назад

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9275

больше 9 лет назад

Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9273

больше 9 лет назад

tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9266

больше 9 лет назад

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9265

больше 9 лет назад

The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9264

больше 9 лет назад

Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9263

почти 9 лет назад

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2016-9262

больше 9 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9243

больше 9 лет назад

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9191

почти 10 лет назад

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9190

почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9189

почти 10 лет назад

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9188

почти 10 лет назад

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9187

почти 10 лет назад

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9186

почти 10 лет назад

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-9185

почти 10 лет назад

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-9181

больше 9 лет назад

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9180

больше 9 лет назад

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2016-9179

больше 9 лет назад

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-9178

почти 10 лет назад

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack memory by triggering failure of a get_user_ex call.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-9276

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 7.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9275

Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

CVSS3: 7.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9273

tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.

CVSS3: 5.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9266

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

CVSS3: 6.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9265

The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9264

Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9263

WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain Flash injection (XSF) attacks by leveraging code contained within the wp-includes/js/mediaelement/flashmediaelement.swf file.

CVSS3: 4.7
2%
Низкий
почти 9 лет назад
ubuntu логотип
CVE-2016-9262

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9243

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9190

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

CVSS3: 7.8
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9189

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

CVSS3: 5.5
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9188

Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

CVSS3: 6.1
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9187

Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9186

Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9185

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

CVSS3: 4.3
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-9181

perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.

CVSS3: 7.1
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9180

perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entities are always expanded, regardless of the option's setting.

CVSS3: 9.1
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9179

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

CVSS3: 7.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-9178

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which allows local users to obtain sensitive information from kernel stack memory by triggering failure of a get_user_ex call.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад

Уязвимостей на страницу