CVE-2016-7543
- EPSS 0.1%
- Veröffentlicht 19.01.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
CVE-2016-7545
- EPSS 0.07%
- Veröffentlicht 19.01.2017 20:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
CVE-2016-9811
- EPSS 0.49%
- Veröffentlicht 13.01.2017 16:59:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
CVE-2016-2090
- EPSS 1.71%
- Veröffentlicht 13.01.2017 16:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Off-by-one vulnerability in the fgetwln function in libbsd before 0.8.2 allows attackers to have unspecified impact via unknown vectors, which trigger a heap-based buffer overflow.
CVE-2016-10027
- EPSS 0.39%
- Veröffentlicht 12.01.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "s...
CVE-2016-9299
- EPSS 86.03%
- Veröffentlicht 12.01.2017 23:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.
CVE-2016-8605
- EPSS 0.09%
- Veröffentlicht 12.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example, mkdir without the optional mod...
CVE-2016-8606
- EPSS 0.34%
- Veröffentlicht 12.01.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
CVE-2016-2312
- EPSS 0.08%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
CVE-2016-7966
- EPSS 0.39%
- Veröffentlicht 23.12.2016 22:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which gre...