Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2016-7571

почти 10 лет назад

Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-7570

почти 10 лет назад

Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7569

больше 9 лет назад

Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7568

почти 10 лет назад

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7567

больше 9 лет назад

Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-7562

больше 9 лет назад

The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7555

больше 9 лет назад

The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7553

больше 9 лет назад

The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2016-7551

больше 9 лет назад

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7550

больше 7 лет назад

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7549

почти 10 лет назад

Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7545

больше 9 лет назад

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-7544

больше 9 лет назад

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7543

больше 9 лет назад

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

CVSS3: 8.4
EPSS: Низкий
ubuntu логотип

CVE-2016-7540

больше 9 лет назад

coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7539

около 9 лет назад

Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7538

больше 9 лет назад

coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7537

больше 9 лет назад

MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7536

больше 9 лет назад

magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2016-7535

больше 9 лет назад

coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted PSD file.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-7571

Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.

CVSS3: 6.1
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7570

Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

CVSS3: 4.3
2%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7569

Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in the embedded layer data in an image.

CVSS3: 5.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7568

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted imagewebp and imagedestroy calls.

CVSS3: 9.8
5%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7567

Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.

CVSS3: 9.8
12%
Средний
больше 9 лет назад
ubuntu логотип
CVE-2016-7562

The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7555

The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.

CVSS3: 5.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7553

The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.

CVSS3: 3.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7551

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allows remote attackers to cause a denial of service (port exhaustion).

CVSS3: 7.5
5%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7550

asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote).

CVSS3: 7.5
2%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2016-7549

Google Chrome before 53.0.2785.113 does not ensure that the recipient of a certain IPC message is a valid RenderFrame or RenderWidget, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) or possibly have unspecified other impact by leveraging access to a renderer process, related to render_frame_host_impl.cc and render_widget_host_impl.cc, as demonstrated by a Password Manager message.

CVSS3: 8.8
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-7545

SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

CVSS3: 8.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7544

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.

CVSS3: 7.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7543

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

CVSS3: 8.4
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7540

coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7539

Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

CVSS3: 7.5
5%
Низкий
около 9 лет назад
ubuntu логотип
CVE-2016-7538

coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7537

MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7536

magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-7535

coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted PSD file.

CVSS3: 6.5
3%
Низкий
больше 9 лет назад

Уязвимостей на страницу