CVE-2016-9104
- EPSS 0.12%
- Veröffentlicht 09.12.2016 22:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in the (1) v9fs_xattr_read and (2) v9fs_xattr_write functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a denial of service (QEMU process crash) via a crafted offset, which tr...
- EPSS 0.12%
- Veröffentlicht 09.12.2016 22:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattribute values before writing to them.
- EPSS 0.1%
- Veröffentlicht 09.12.2016 22:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) via a large number of Txattrcreate messages with t...
- EPSS 0.12%
- Veröffentlicht 09.12.2016 22:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in hw/net/eepro100.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by repeatedly unplugging an i8255x (PRO100) NIC device.
CVE-2016-1248
- EPSS 15.94%
- Veröffentlicht 23.11.2016 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
CVE-2016-9376
- EPSS 1.48%
- Veröffentlicht 17.11.2016 05:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length valu...
CVE-2016-9375
- EPSS 1.48%
- Veröffentlicht 17.11.2016 05:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.
CVE-2016-9374
- EPSS 1.22%
- Veröffentlicht 17.11.2016 05:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable prope...
CVE-2016-9373
- EPSS 1.22%
- Veröffentlicht 17.11.2016 05:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dcerpc-spoolss...
CVE-2016-5195
- EPSS 94.18%
- Veröffentlicht 10.11.2016 21:59:00
- Zuletzt bearbeitet 04.11.2025 16:15:37
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in Oc...