CVE-2016-4470
- EPSS 0.06%
- Veröffentlicht 27.06.2016 10:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a craft...
CVE-2016-0758
- EPSS 0.2%
- Veröffentlicht 27.06.2016 10:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.
CVE-2016-3698
- EPSS 0.77%
- Veröffentlicht 13.06.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity d...
CVE-2016-2818
- EPSS 0.59%
- Veröffentlicht 13.06.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
- EPSS 1.2%
- Veröffentlicht 09.06.2016 16:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
CVE-2016-2150
- EPSS 0.07%
- Veröffentlicht 09.06.2016 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
- EPSS 16.15%
- Veröffentlicht 09.06.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
CVE-2015-5261
- EPSS 0.05%
- Veröffentlicht 07.06.2016 14:06:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.
CVE-2015-5260
- EPSS 0.13%
- Veröffentlicht 07.06.2016 14:06:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter...
CVE-2016-0376
- EPSS 1.93%
- Veröffentlicht 03.06.2016 14:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not pr...