CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96133  CVE-2016-9313  Candidate  security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.  Assigned (20161114)  None (candidate not yet proposed)    View
96134  CVE-2016-9314  Candidate  Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup the system configuration and download it onto their local machine. This backup file contains sensitive information like passwd/shadow files, RSA certificates, Private Keys and Default Passphrase, etc. This was resolved in Version 6.5 CP 1737.  Assigned (20161114)  None (candidate not yet proposed)    View
96135  CVE-2016-9315  Candidate  Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to change Master Admin"s password and/or add new admin accounts. This was resolved in Version 6.5 CP 1737.  Assigned (20161114)  None (candidate not yet proposed)    View
96136  CVE-2016-9316  Candidate  Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.  Assigned (20161114)  None (candidate not yet proposed)    View
96137  CVE-2016-9317  Candidate  The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.  Assigned (20161114)  None (candidate not yet proposed)    View

Page 18620 of 20943, showing 5 records out of 104715 total, starting on record 93096, ending on 93100

Actions