| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2016-1572 |
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid. Published: January 22, 2016; 10:59:07 AM -0500 |
V3.0: 8.4 HIGH V2.0: 4.6 MEDIUM |
| CVE-2016-0616 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. Published: January 20, 2016; 10:02:39 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0610 |
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier and MariaDB before 10.0.22 and 10.1.x before 10.1.9 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. Published: January 20, 2016; 10:02:37 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0609 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges. Published: January 20, 2016; 10:02:36 PM -0500 |
V3.x:(not available) V2.0: 1.7 LOW |
| CVE-2016-0608 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF. Published: January 20, 2016; 10:02:35 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0606 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption. Published: January 20, 2016; 10:02:32 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0600 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. Published: January 20, 2016; 10:02:28 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0598 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:26 PM -0500 |
V3.x:(not available) V2.0: 3.5 LOW |
| CVE-2016-0597 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. Published: January 20, 2016; 10:02:25 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0596 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. Published: January 20, 2016; 10:02:24 PM -0500 |
V3.x:(not available) V2.0: 4.0 MEDIUM |
| CVE-2016-0592 |
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and before 5.0.14 allows local users to affect availability via unknown vectors related to Core. Published: January 20, 2016; 10:02:21 PM -0500 |
V3.x:(not available) V2.0: 2.1 LOW |
| CVE-2016-0546 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that these are multiple buffer overflows in the mysqlshow tool that allow remote database servers to have unspecified impact via a long table or database name. Published: January 20, 2016; 10:01:33 PM -0500 |
V3.x:(not available) V2.0: 7.2 HIGH |
| CVE-2016-0505 |
Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options. Published: January 20, 2016; 10:00:53 PM -0500 |
V3.x:(not available) V2.0: 6.8 MEDIUM |
| CVE-2016-0495 |
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 4.3.36 and 5.0.14 allows remote attackers to affect availability via unknown vectors related to Core. Published: January 20, 2016; 10:00:43 PM -0500 |
V3.x:(not available) V2.0: 4.3 MEDIUM |
| CVE-2015-8605 |
ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an invalid length field in a UDP IPv4 packet. Published: January 14, 2016; 5:59:00 PM -0500 |
V3.0: 6.5 MEDIUM V2.0: 5.7 MEDIUM |
| CVE-2015-8607 |
The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, which might allow context-dependent attackers to bypass the taint protection mechanism via a crafted string. Published: January 13, 2016; 10:59:01 AM -0500 |
V3.0: 7.3 HIGH V2.0: 7.5 HIGH |
| CVE-2016-1232 |
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack. Published: January 12, 2016; 3:59:10 PM -0500 |
V3.0: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2016-1231 |
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path. Published: January 12, 2016; 3:59:09 PM -0500 |
V3.0: 5.9 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2015-1779 |
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section. Published: January 12, 2016; 2:59:00 PM -0500 |
V3.1: 8.6 HIGH V2.0: 7.8 HIGH |
| CVE-2015-7512 |
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet. Published: January 08, 2016; 4:59:02 PM -0500 |
V3.1: 9.0 CRITICAL V2.0: 6.8 MEDIUM |