CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93911  CVE-2016-7091  Candidate  sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.  Assigned (20160825)  None (candidate not yet proposed)    View
93912  CVE-2016-7092  Candidate  The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.  Assigned (20160825)  None (candidate not yet proposed)    View
93913  CVE-2016-7093  Candidate  Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.  Assigned (20160825)  None (candidate not yet proposed)    View
93914  CVE-2016-7094  Candidate  Buffer overflow in Xen 4.7.x and earlier allows local x86 HVM guest OS administrators on guests running with shadow paging to cause a denial of service via a pagetable update.  Assigned (20160825)  None (candidate not yet proposed)    View
93915  CVE-2016-7095  Candidate  Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.  Assigned (20160826)  None (candidate not yet proposed)    View

Page 18783 of 20943, showing 5 records out of 104715 total, starting on record 93911, ending on 93915

Actions