NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81736 | CVE-2016-2781 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal"s input buffer. | 2 | 2.1 | Low | 2017-02-28 | 2017-02-27 | View | |
| 18771 | CVE-2016-2782 | The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint. | 2 | 4.9 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 18772 | CVE-2016-2784 | CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request. | 2 | 2.6 | Low | 2017-01-19 | 2016-05-26 | View | |
| 18773 | CVE-2016-2785 | Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding. | 2 | 7.5 | High | 2017-01-19 | 2016-06-14 | View | |
| 18774 | CVE-2016-2786 | The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certificates, which might allow remote attackers to spoof brokers and execute arbitrary commands via a crafted certificate. | 2 | 7.5 | High | 2017-01-19 | 2016-06-14 | View |
Page 15667 of 17672, showing 5 records out of 88360 total, starting on record 78331, ending on 78335