CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87657  CVE-2016-10151  Candidate  The hesiod_init function in lib/hesiod.c in Hesiod 3.2.1 compares EUID with UID to determine whether to use configurations from environment variables, which allows local users to gain privileges via the (1) HESIOD_CONFIG or (2) HES_DOMAIN environment variable and leveraging certain SUID/SGUID binary.  Assigned (20170120)  None (candidate not yet proposed)    View
87658  CVE-2016-10152  Candidate  The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.  Assigned (20170120)  None (candidate not yet proposed)    View
87659  CVE-2016-10153  Candidate  The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging reliance on earlier net/ceph/crypto.c code.  Assigned (20170120)  None (candidate not yet proposed)    View
87660  CVE-2016-10154  Candidate  The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a scatterlist.  Assigned (20170120)  None (candidate not yet proposed)    View
87661  CVE-2016-10155  Candidate  Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.  Assigned (20170120)  None (candidate not yet proposed)    View

Page 19839 of 20943, showing 5 records out of 104715 total, starting on record 99191, ending on 99195

Actions