Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 78 702

Количество 78 702

ubuntu логотип

CVE-2016-10142

больше 9 лет назад

An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, unfortunately, even nodes that already implement [RFC6946] can be subject to DoS attacks as a result of the generation of IPv6 atomic fragments. Let us assume that Host A is communicating with Host B and that, as a result of the wide...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-10140

больше 9 лет назад

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-1013

больше 10 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2016-10134

больше 9 лет назад

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

CVSS3: 9.8
EPSS: Высокий
ubuntu логотип

CVE-2016-10130

больше 9 лет назад

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2016-1012

больше 10 лет назад

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10129

больше 9 лет назад

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2016-10128

больше 9 лет назад

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10127

больше 9 лет назад

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

CVSS3: 9
EPSS: Низкий
ubuntu логотип

CVE-2016-10124

больше 9 лет назад

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2016-10123

больше 9 лет назад

Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10122

больше 9 лет назад

Firejail does not properly clean environment variables, which allows local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10121

больше 9 лет назад

Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10120

больше 9 лет назад

Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1011

больше 10 лет назад

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2016-10119

больше 9 лет назад

Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-10118

больше 9 лет назад

Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2016-10117

больше 9 лет назад

Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2016-1010

больше 10 лет назад

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2016-10109

больше 9 лет назад

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-10142

An issue was discovered in the IPv6 protocol specification, related to ICMP Packet Too Big (PTB) messages. (The scope of this CVE is all affected IPv6 implementations from all vendors.) The security implications of IP fragmentation have been discussed at length in [RFC6274] and [RFC7739]. An attacker can leverage the generation of IPv6 atomic fragments to trigger the use of fragmentation in an arbitrary IPv6 flow (in scenarios in which actual fragmentation of packets is not needed) and can subsequently perform any type of fragmentation-based attack against legacy IPv6 nodes that do not implement [RFC6946]. That is, employing fragmentation where not actually needed allows for fragmentation-based attack vectors to be employed, unnecessarily. We note that, unfortunately, even nodes that already implement [RFC6946] can be subject to DoS attacks as a result of the generation of IPv6 atomic fragments. Let us assume that Host A is communicating with Host B and that, as a result of the wide...

CVSS3: 8.6
3%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10140

Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.

CVSS3: 7.5
7%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1013

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1011, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

CVSS3: 8.8
23%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-10134

SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

CVSS3: 9.8
83%
Высокий
больше 9 лет назад
ubuntu логотип
CVE-2016-10130

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.

CVSS3: 5.9
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1012

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1020, CVE-2016-1021, CVE-2016-1022, CVE-2016-1023, CVE-2016-1024, CVE-2016-1025, CVE-2016-1026, CVE-2016-1027, CVE-2016-1028, CVE-2016-1029, CVE-2016-1032, and CVE-2016-1033.

CVSS3: 8.8
4%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2016-10129

The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.

CVSS3: 7.5
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10128

Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.

CVSS3: 9.8
4%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10127

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

CVSS3: 9
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10124

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the container.

CVSS3: 8.6
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10123

Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10122

Firejail does not properly clean environment variables, which allows local users to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10121

Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10120

Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1011

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1013, CVE-2016-1016, CVE-2016-1017, and CVE-2016-1031.

CVSS3: 8.8
26%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-10119

Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10118

Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.

CVSS3: 3.3
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-10117

Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

CVSS3: 7.8
0%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2016-1010

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0963 and CVE-2016-0993.

CVSS3: 8.8
19%
Средний
больше 10 лет назад
ubuntu логотип
CVE-2016-10109

Use-after-free vulnerability in pcsc-lite before 1.8.20 allows a remote attackers to cause denial of service (crash) via a command that uses "cardsList" after the handle has been released through the SCardReleaseContext function.

CVSS3: 7.5
4%
Низкий
больше 9 лет назад

Уязвимостей на страницу