CVE-2015-2877
- EPSS 0.11%
- Veröffentlicht 03.03.2017 11:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection...
CVE-2016-2568
- EPSS 0.13%
- Veröffentlicht 13.02.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CVE-2016-3616
- EPSS 1.4%
- Veröffentlicht 13.02.2017 18:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
CVE-2016-7091
- EPSS 0.07%
- Veröffentlicht 22.12.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted ...
CVE-2016-9675
- EPSS 0.8%
- Veröffentlicht 22.12.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.
CVE-2016-5195
- EPSS 94.18%
- Veröffentlicht 10.11.2016 21:59:00
- Zuletzt bearbeitet 04.11.2025 16:15:37
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...
CVE-2016-1000033
- EPSS 0.41%
- Veröffentlicht 25.10.2016 14:29:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Shotwell version 0.22.0 (and possibly other versions) is vulnerable to a TLS/SSL certification validation flaw resulting in a potential for man in the middle attacks.
- EPSS 89.58%
- Veröffentlicht 20.09.2016 18:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow loc...
CVE-2016-2183
- EPSS 40.02%
- Veröffentlicht 01.09.2016 00:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birth...
CVE-2016-5766
- EPSS 16.23%
- Veröffentlicht 07.08.2016 10:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based ...