LiveActive security incident?Get immediate response
CVE archive

December 2016

Browse CVE records published in December 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 530 matching CVEs · Page 5 of 11.

High · CVSS 7

CVE-2016-9034: An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable leading to an out of bounds memory access and could result in potential privilege escalation. This vulnerability is distinct from CVE-2016-9032.

Published Dec 14, 2016 · Updated Aug 6, 2024

High · CVSS 7.5

CVE-2016-9036: An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck...

An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.

Published Dec 23, 2016 · Updated Aug 6, 2024

High · CVSS 7.5

CVE-2016-9037: An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarant...

An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key's value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server.

Published Dec 23, 2016 · Updated Aug 6, 2024

High · CVSS 7

CVE-2016-9032: An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable leading to an out of bounds memory access and could result in potential privilege escalation. This vulnerability is distinct from CVE-2016-9034.

Published Dec 14, 2016 · Updated Aug 6, 2024

High · CVSS 7

CVE-2016-9033: An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable leading to an out of bounds memory access and could result in potential privilege escalation. This vulnerability is distinct from CVE-2016-9035.

Published Dec 14, 2016 · Updated Aug 6, 2024

High · CVSS 7

CVE-2016-9035: An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable leading to an out of bounds memory access and could result in potential privilege escalation. This vulnerability is distinct from CVE-2016-9033.

Published Dec 14, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9013: Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a te...

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

Published Dec 9, 2016 · Updated Aug 6, 2024

High · CVSS 7.8

CVE-2016-9031: An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a kernel panic and potentially be leveraged into a full privilege escalation vulnerability. This vulnerability is distinct from CVE-2016-8733.

Published Dec 14, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8817: All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmk...

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer overflow, leading to denial of service or potential escalation of privileges.

Published Dec 16, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8816: All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmk...

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

Published Dec 16, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8815: All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmk...

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

Published Dec 16, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8822: All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmk...

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000E, 0x600000F, and 0x6000010 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

Published Dec 16, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8820: All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmk...

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source of a strcpy() call, leading to denial of service or information disclosure.

Published Dec 16, 2016 · Updated Aug 6, 2024

High · CVSS 7.5

CVE-2016-8707: An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's conve...

An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

Published Dec 23, 2016 · Updated Aug 6, 2024

High · CVSS 7.8

CVE-2016-8733: An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system.

An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be leveraged into a full privilege escalation vulnerability. This vulnerability is distinct from CVE-2016-9031.

Published Dec 14, 2016 · Updated Aug 6, 2024