CVE-2013-1430
- EPSS 0.35%
- Veröffentlicht 16.12.2016 09:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a know...
CVE-2016-9964
- EPSS 1.21%
- Veröffentlicht 16.12.2016 09:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
redirect() in bottle.py in bottle 0.12.10 doesn't filter a "\r\n" sequence, which leads to a CRLF attack, as demonstrated by a redirect("233\r\nSet-Cookie: name=salt") call.
CVE-2016-6313
- EPSS 2.69%
- Veröffentlicht 13.12.2016 20:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 make it easier for attackers to obtain the values of 160 bits by leveraging knowledge of the previous 46...
CVE-2016-7440
- EPSS 0.08%
- Veröffentlicht 13.12.2016 16:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
CVE-2016-9427
- EPSS 3.12%
- Veröffentlicht 12.12.2016 02:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.
CVE-2016-7421
- EPSS 0.11%
- Veröffentlicht 10.12.2016 00:59:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit process IO loop to the...
CVE-2016-7170
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:16
- Zuletzt bearbeitet 06.05.2026 22:30:45
The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to cursor.mask[] and cursor.image[...
CVE-2016-7156
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging an incorrect cast.
CVE-2016-7155
- EPSS 0.08%
- Veröffentlicht 10.12.2016 00:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.
- EPSS 0.86%
- Veröffentlicht 10.12.2016 00:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.