CVE-2015-8325
- EPSS 0.09%
- Veröffentlicht 01.05.2016 01:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_environment files in user home directories, allows local users to gain privileges by triggering a crafted...
CVE-2016-3672
- EPSS 0.03%
- Veröffentlicht 27.04.2016 17:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, a...
CVE-2016-3156
- EPSS 0.03%
- Veröffentlicht 27.04.2016 17:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.
CVE-2016-3135
- EPSS 0.2%
- Veröffentlicht 27.04.2016 17:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLA...
CVE-2016-2383
- EPSS 0.08%
- Veröffentlicht 27.04.2016 17:59:10
- Zuletzt bearbeitet 06.05.2026 22:30:45
The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and th...
CVE-2016-2184
- EPSS 0.19%
- Veröffentlicht 27.04.2016 17:59:09
- Zuletzt bearbeitet 06.05.2026 22:30:45
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) v...
CVE-2016-2069
- EPSS 0.06%
- Veröffentlicht 27.04.2016 17:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.
- EPSS 3.61%
- Veröffentlicht 27.04.2016 17:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
CVE-2016-4002
- EPSS 7.87%
- Veröffentlicht 26.04.2016 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
Buffer overflow in the mipsnet_receive function in hw/net/mipsnet.c in QEMU, when the guest NIC is configured to accept large packets, allows remote attackers to cause a denial of service (memory corruption and QEMU crash) or possibly execute arbitra...
CVE-2016-3074
- EPSS 60.49%
- Veröffentlicht 26.04.2016 14:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflo...