CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93936  CVE-2016-7116  Candidate  Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string.  Assigned (20160830)  None (candidate not yet proposed)    View
93937  CVE-2016-7117  Candidate  Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.  Assigned (20160830)  None (candidate not yet proposed)    View
93938  CVE-2016-7118  Candidate  fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem.  Assigned (20160831)  None (candidate not yet proposed)    View
93939  CVE-2016-7119  Candidate  Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.  Assigned (20160831)  None (candidate not yet proposed)    View
93940  CVE-2016-7120  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160901)  None (candidate not yet proposed)    View

Page 18788 of 20943, showing 5 records out of 104715 total, starting on record 93936, ending on 93940

Actions