CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
95856 | CVE-2016-9036 | Candidate | An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool"s Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability. | Assigned (20161026) | None (candidate not yet proposed) | View | |
95857 | CVE-2016-9037 | Candidate | An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key"s value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server. | Assigned (20161026) | None (candidate not yet proposed) | View | |
95858 | CVE-2016-9038 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161026) | None (candidate not yet proposed) | View | |
95859 | CVE-2016-9039 | Candidate | An exploitable denial of service exists in the the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory exhaustion, resulting in a full system denial of service. | Assigned (20161026) | None (candidate not yet proposed) | View | |
95860 | CVE-2016-9040 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161026) | None (candidate not yet proposed) | View |
Page 19172 of 20943, showing 5 records out of 104715 total, starting on record 95856, ending on 95860