CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96736 | CVE-2016-9916 | Candidate | Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend. | Assigned (20161208) | None (candidate not yet proposed) | View | |
96737 | CVE-2016-9917 | Candidate | In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash. | Assigned (20161208) | None (candidate not yet proposed) | View | |
96738 | CVE-2016-9918 | Candidate | In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash. | Assigned (20161208) | None (candidate not yet proposed) | View | |
96739 | CVE-2016-9919 | Candidate | The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet. | Assigned (20161208) | None (candidate not yet proposed) | View | |
96740 | CVE-2016-9920 | Candidate | steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message. | Assigned (20161208) | None (candidate not yet proposed) | View |
Page 19348 of 20943, showing 5 records out of 104715 total, starting on record 96736, ending on 96740