CVE-2016-5824
- EPSS 0.44%
- Veröffentlicht 27.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
CVE-2016-9446
- EPSS 1.28%
- Veröffentlicht 23.01.2017 21:59:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
CVE-2016-9401
- EPSS 0.03%
- Veröffentlicht 23.01.2017 21:59:02
- Zuletzt bearbeitet 06.08.2025 22:15:28
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2016-7545
- EPSS 0.04%
- Veröffentlicht 19.01.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
CVE-2016-5198
- EPSS 69.4%
- Veröffentlicht 19.01.2017 05:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading t...
CVE-2016-9811
- EPSS 0.49%
- Veröffentlicht 13.01.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVE-2016-7426
- EPSS 38.91%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses wit...
CVE-2016-7091
- EPSS 0.07%
- Veröffentlicht 22.12.2016 21:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted ...
CVE-2014-8241
- EPSS 0.32%
- Veröffentlicht 14.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052.
CVE-2016-7865
- EPSS 11.16%
- Veröffentlicht 08.11.2016 17:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.