CVE-2016-10027
- EPSS 0.39%
- Veröffentlicht 12.01.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "s...
CVE-2016-9299
- EPSS 69.03%
- Veröffentlicht 12.01.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVE-2016-8605
- EPSS 0.09%
- Veröffentlicht 12.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mod...
CVE-2016-8606
- EPSS 0.34%
- Veröffentlicht 12.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
CVE-2016-2312
- EPSS 0.08%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
CVE-2016-7966
- EPSS 0.19%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which gre...
CVE-2016-2334
- EPSS 16.3%
- Veröffentlicht 13.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
CVE-2016-7953
- EPSS 0.91%
- Veröffentlicht 13.12.2016 20:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
CVE-2016-7952
- EPSS 0.86%
- Veröffentlicht 13.12.2016 20:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.
CVE-2016-7951
- EPSS 0.71%
- Veröffentlicht 13.12.2016 20:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.