CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94226  CVE-2016-7406  Candidate  Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.  Assigned (20160909)  None (candidate not yet proposed)    View
94227  CVE-2016-7407  Candidate  The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.  Assigned (20160909)  None (candidate not yet proposed)    View
94228  CVE-2016-7408  Candidate  The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.  Assigned (20160909)  None (candidate not yet proposed)    View
94229  CVE-2016-7409  Candidate  The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.  Assigned (20160909)  None (candidate not yet proposed)    View
94230  CVE-2016-7410  Candidate  The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18846 of 20943, showing 5 records out of 104715 total, starting on record 94226, ending on 94230

Actions