Total
5442 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2016-6903 | 1 Lshell Project | 1 Lshell | 2017-04-27 | 9.0 HIGH | 9.9 CRITICAL |
| lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. | |||||
| CVE-2016-6902 | 1 Lshell Project | 1 Lshell | 2017-04-27 | 9.0 HIGH | 9.9 CRITICAL |
| lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. | |||||
| CVE-2016-3114 | 1 Kallithea | 1 Kallithea | 2017-04-27 | 4.0 MEDIUM | 6.5 MEDIUM |
| Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access. | |||||
| CVE-2016-10345 | 1 Phusion | 1 Passenger | 2017-04-24 | 4.6 MEDIUM | 7.8 HIGH |
| In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user. | |||||
| CVE-2016-6727 | 1 Google | 1 Android | 2017-04-24 | 10.0 HIGH | 9.8 CRITICAL |
| The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code. | |||||
| CVE-2016-0727 | 1 Canonical | 1 Ubuntu Linux | 2017-04-20 | 7.2 HIGH | 7.8 HIGH |
| The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows local users with access to the ntp account to write to arbitrary files and consequently gain privileges via vectors involving statistics directory cleanup. | |||||
| CVE-2016-5856 | 2 Google, Linux | 2 Android, Linux Kernel | 2017-04-19 | 7.6 HIGH | 7.0 HIGH |
| Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857. | |||||
| CVE-2016-10121 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. | |||||
| CVE-2016-10122 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail does not properly clean environment variables, which allows local users to gain privileges. | |||||
| CVE-2016-10123 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. | |||||
| CVE-2016-10120 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. | |||||
| CVE-2016-10119 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. | |||||
| CVE-2016-10118 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 2.1 LOW | 3.3 LOW |
| Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /. | |||||
| CVE-2016-10117 | 1 Firejail Project | 1 Firejail | 2017-04-19 | 7.2 HIGH | 7.8 HIGH |
| Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. | |||||
| CVE-2016-8237 | 1 Lenovo | 1 Updates | 2017-04-17 | 9.3 HIGH | 8.1 HIGH |
| Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code. | |||||
| CVE-2016-8235 | 1 Lenovo | 1 Customer Care Software Development Kit | 2017-04-17 | 7.2 HIGH | 7.8 HIGH |
| Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges. | |||||
| CVE-2016-5071 | 1 Sierrawireless | 2 Aleos Firmware, Gx 440 | 2017-04-14 | 10.0 HIGH | 8.8 HIGH |
| Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root. | |||||
| CVE-2015-7274 | 1 Dell | 2 Integrated Remote Access Controller 6, Integrated Remote Access Controller Firmware | 2017-04-14 | 6.5 MEDIUM | 8.8 HIGH |
| Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands. | |||||
| CVE-2016-9197 | 1 Cisco | 1 Mobility Services Engine | 2017-04-13 | 7.2 HIGH | 6.7 MEDIUM |
| A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers could allow an authenticated, local attacker to obtain access to the underlying operating system shell with root-level privileges. More Information: CSCvb70351. Known Affected Releases: 8.3(102.0). | |||||
| CVE-2016-10318 | 1 Linux | 1 Linux Kernel | 2017-04-11 | 4.0 MEDIUM | 6.5 MEDIUM |
| A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the Linux kernel before 4.7.4 allows a user to assign an encryption policy to a directory owned by a different user, potentially creating a denial of service. | |||||
