CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94361  CVE-2016-7541  Candidate  Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during IPS signature updates when the FortiGate"s IPSengine is configured in flow mode. All FortiGate versions with IPS configured in proxy mode (the default mode) are not affected.  Assigned (20160909)  None (candidate not yet proposed)    View
94362  CVE-2016-7542  Candidate  A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may therefore be able to crack them.  Assigned (20160909)  None (candidate not yet proposed)    View
94363  CVE-2016-7543  Candidate  Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.  Assigned (20160909)  None (candidate not yet proposed)    View
94364  CVE-2016-7544  Candidate  Crypto++ 5.6.4 incorrectly uses Microsoft"s stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.  Assigned (20160909)  None (candidate not yet proposed)    View
94365  CVE-2016-7545  Candidate  SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18873 of 20943, showing 5 records out of 104715 total, starting on record 94361, ending on 94365

Actions