CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93936 | CVE-2016-7116 | Candidate | Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot) in an unspecified string. | Assigned (20160830) | None (candidate not yet proposed) | View | |
93937 | CVE-2016-7117 | Candidate | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing. | Assigned (20160830) | None (candidate not yet proposed) | View | |
93938 | CVE-2016-7118 | Candidate | fs/fcntl.c in the "aufs 3.2.x+setfl-debian" patch in the linux-image package 3.2.0-4 (kernel 3.2.81-1) in Debian wheezy mishandles F_SETFL fcntl calls on directories, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via standard filesystem operations, as demonstrated by scp from an AUFS filesystem. | Assigned (20160831) | None (candidate not yet proposed) | View | |
93939 | CVE-2016-7119 | Candidate | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. | Assigned (20160831) | None (candidate not yet proposed) | View | |
93940 | CVE-2016-7120 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160901) | None (candidate not yet proposed) | View |
Page 18788 of 20943, showing 5 records out of 104715 total, starting on record 93936, ending on 93940