Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 096

Количество 79 096

ubuntu логотип

CVE-2016-3722

больше 10 лет назад

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-3721

больше 10 лет назад

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2016-3720

больше 10 лет назад

XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-3718

больше 10 лет назад

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

CVSS3: 5.5
EPSS: Высокий
ubuntu логотип

CVE-2016-3717

больше 10 лет назад

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

CVSS3: 5.5
EPSS: Средний
ubuntu логотип

CVE-2016-3716

больше 10 лет назад

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

CVSS3: 3.3
EPSS: Средний
ubuntu логотип

CVE-2016-3715

больше 10 лет назад

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

CVSS3: 5.5
EPSS: Высокий
ubuntu логотип

CVE-2016-3714

больше 10 лет назад

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CVSS3: 8.4
EPSS: Критический
ubuntu логотип

CVE-2016-3713

около 10 лет назад

The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.

CVSS3: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2016-3712

больше 10 лет назад

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-3711

больше 10 лет назад

HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2016-3710

больше 10 лет назад

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-3709

около 4 лет назад

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2016-3707

около 10 лет назад

The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2016-3706

больше 10 лет назад

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-3705

больше 10 лет назад

The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-3699

почти 10 лет назад

The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2016-3698

больше 10 лет назад

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2016-3697

больше 10 лет назад

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-3695

больше 8 лет назад

The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-3722

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3721

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3720

XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.

CVSS3: 9.8
3%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3718

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

CVSS3: 5.5
77%
Высокий
больше 10 лет назад
ubuntu логотип
CVE-2016-3717

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

CVSS3: 5.5
20%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-3716

The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.

CVSS3: 3.3
11%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-3715

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

CVSS3: 5.5
75%
Высокий
больше 10 лет назад
ubuntu логотип
CVE-2016-3714

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

CVSS3: 8.4
97%
Критический
больше 10 лет назад
ubuntu логотип
CVE-2016-3713

The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.

CVSS3: 7.1
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-3712

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by editing VGA registers in VBE mode.

CVSS3: 5.5
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3711

HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.

CVSS3: 3.3
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3710

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.

CVSS3: 8.8
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3709

Possible cross-site scripting vulnerability in libxml after commit 960f0e2.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2016-3707

The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

CVSS3: 8.1
3%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2016-3706

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.

CVSS3: 7.5
6%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3705

The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of nested entity references.

CVSS3: 7.5
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3699

The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.

CVSS3: 7.4
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2016-3698

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

CVSS3: 8.1
4%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3697

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

CVSS3: 7.8
0%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-3695

The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.

CVSS3: 5.5
1%
Низкий
больше 8 лет назад

Уязвимостей на страницу