CVE-2016-3706
- EPSS 1.94%
- Veröffentlicht 10.06.2016 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnera...
CVE-2016-2150
- EPSS 0.07%
- Veröffentlicht 09.06.2016 16:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
- EPSS 16.15%
- Veröffentlicht 09.06.2016 16:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.
CVE-2016-2335
- EPSS 1.8%
- Veröffentlicht 07.06.2016 14:06:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation D...
CVE-2015-5231
- EPSS 0.06%
- Veröffentlicht 07.06.2016 14:06:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via (1) process dumps or (2) ptrace access.
CVE-2015-5228
- EPSS 0.14%
- Veröffentlicht 07.06.2016 14:06:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing files via unspecified vectors related to a directory path.
CVE-2016-1703
- EPSS 1%
- Veröffentlicht 05.06.2016 23:59:33
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
CVE-2016-1702
- EPSS 1.42%
- Veröffentlicht 05.06.2016 23:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serial...
CVE-2016-1701
- EPSS 1.35%
- Veröffentlicht 05.06.2016 23:59:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...
CVE-2016-1700
- EPSS 1.72%
- Veröffentlicht 05.06.2016 23:59:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly...