CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87499  CVE-2016-10008  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161219)  None (candidate not yet proposed)    View
87500  CVE-2016-10009  Candidate  Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.  Assigned (20161219)  None (candidate not yet proposed)    View
87502  CVE-2016-10010  Candidate  sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.  Assigned (20161219)  None (candidate not yet proposed)    View
87503  CVE-2016-10011  Candidate  authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.  Assigned (20161219)  None (candidate not yet proposed)    View
87504  CVE-2016-10012  Candidate  The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.  Assigned (20161219)  None (candidate not yet proposed)    View

Page 1486 of 20943, showing 5 records out of 104715 total, starting on record 7426, ending on 7430

Actions