Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 702

Количество 78 702

ubuntu логотип

CVE-2016-10377

больше 9 лет назад

In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10376

больше 9 лет назад

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10375

больше 9 лет назад

Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10374

больше 9 лет назад

perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10371

больше 9 лет назад

The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10369

больше 9 лет назад

unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10351

больше 9 лет назад

Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10350

больше 9 лет назад

The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10349

больше 9 лет назад

The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10345

больше 9 лет назад

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1033

больше 10 лет назад

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1032.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1032

больше 10 лет назад

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1033.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10328

больше 9 лет назад

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10327

больше 9 лет назад

LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10326

больше 9 лет назад

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10325

больше 9 лет назад

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10324

больше 9 лет назад

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10321

больше 9 лет назад

web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1031

больше 10 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10318

больше 9 лет назад

A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-10377

In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.

CVSS3: 8.8
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10376

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions.

CVSS3: 4.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10375

Yodl before 3.07.01 has a Buffer Over-read in the queue_push function in queue/queuepush.c.

CVSS3: 9.8
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10374

perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current working directory for certain output files and does not have a symlink-attack protection mechanism, which allows local users to overwrite arbitrary files by creating a symlink, as demonstrated by creating a perltidy.ERR symlink that the victim cannot delete.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10371

The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.

CVSS3: 5.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10369

unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10351

Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.

CVSS3: 5.5
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10350

The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10349

The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

CVSS3: 5.5
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10345

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1033

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1032.

CVSS3: 8.8
4%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-1032

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1012, CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, and CVE-2016-1033.

CVSS3: 8.8
4%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-10328

FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10327

LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10326

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10325

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10324

In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.

CVSS3: 9.8
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10321

web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.

CVSS3: 9.8
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1031

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1013, CVE-2016-1016, and CVE-2016-1017.

CVSS3: 8.8
5%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-10318

A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service.

CVSS3: 6.5
2%
Низкий
больше 9 лет назад

Уязвимостей на страницу