CVE-2016-5337
- EPSS 0.05%
- Veröffentlicht 14.06.2016 14:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.
CVE-2016-5238
- EPSS 0.06%
- Veröffentlicht 14.06.2016 14:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.
CVE-2016-4478
- EPSS 0.59%
- Veröffentlicht 13.06.2016 19:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
CVE-2016-3698
- EPSS 0.77%
- Veröffentlicht 13.06.2016 19:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity d...
CVE-2016-2831
- EPSS 0.67%
- Veröffentlicht 13.06.2016 10:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing att...
CVE-2016-2828
- EPSS 2.1%
- Veröffentlicht 13.06.2016 10:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
CVE-2016-2822
- EPSS 0.7%
- Veröffentlicht 13.06.2016 10:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
CVE-2016-2821
- EPSS 2.86%
- Veröffentlicht 13.06.2016 10:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (hea...
CVE-2016-2819
- EPSS 66.64%
- Veröffentlicht 13.06.2016 10:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.
CVE-2016-2818
- EPSS 0.59%
- Veröffentlicht 13.06.2016 10:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...