Pty/tty device Race Condition Vulnerability (CVE-2014-0196), ptycve-2014-0196Prerequisites
1. pty/tty. A product with a long history, mainly used for terminal input and output. Introductory article: http://www.linusakesson.net/programming/tty/
2. slab. It is mainly used to allocate memory of a specific size to prevent memory fragments and holes. It is similar to Lookaside in windows kernel. Baidu encyclopedia related articles: http://baike.baidu.com/v
Catalog1 . Description2. Analysis3. POC4. Solution1. DescriptionMultipartstream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, a Llows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-type header That bypasses a loop ' s intended exit conditionsThe Apache Commons FileUpload 1.3.1 and Multipartstream.java files in the previous version of Apache Tomcat and JBoss Web have security vulner
Honeywell 93gas Detector information leakage (CVE-2015-7908)Honeywell 93gas Detector information leakage (CVE-2015-7908)
Release date:Updated on:Affected Systems:
Honeywell Midas gas detectors Honeywell Midas Black gas detectors
Description:
CVE (CAN) ID: CVE-2015-7908Midas and Midas Black gas detectors are dete
Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)Libxml2 xmlParseXMLDecl function Information Leakage Vulnerability (CVE-2015-8317)
Release date:Updated on:Affected Systems:
Libxml libxml2
Description:
CVE (CAN) ID: CVE-2015-8317Libxml2 is an XML Parser and markup tool set.Versio
Isc bind Denial of Service Vulnerability (CVE-2015-8461)Isc bind Denial of Service Vulnerability (CVE-2015-8461)
Release date:Updated on:Affected Systems:
Isc bind 9. x-9.9.8-P2Isc bind 9.10.x-9.10.3-P2
Description:
CVE (CAN) ID: CVE-2015-8461BIND is a widely used DNS protocol.In isc bind 9. x-9.9.8-P2, 9.10.x-9.
Mozilla Firefox memory corruption and DoS Vulnerability (CVE-2015-7180)Mozilla Firefox memory corruption and DoS Vulnerability (CVE-2015-7180)
Release date:Updated on:Affected Systems:
Mozilla Firefox lt; 41.0Mozilla Firefox lt; 38.3
Description:
CVE (CAN) ID: CVE-2015-7180Mozilla Firefox is an open-source web
Mozilla Firefox InitTextures Function Denial of Service Vulnerability (CVE-2015-4517)Mozilla Firefox InitTextures Function Denial of Service Vulnerability (CVE-2015-4517)
Release date:Updated on:Affected Systems:
Mozilla Firefox lt; 41.0Mozilla Firefox lt; 38.3
Description:
CVE (CAN) ID: CVE-2015-4517Mozilla Fi
Mozilla Firefox buffer overflow and Denial of Service Vulnerability (CVE-2015-7179)Mozilla Firefox buffer overflow and Denial of Service Vulnerability (CVE-2015-7179)
Release date:Updated on:Affected Systems:
Mozilla Firefox Mozilla Firefox
Description:
CVE (CAN) ID: CVE-2015-7179Mozilla Firefox is an open-source web
MediaWiki Quiz extended Denial of Service Vulnerability (CVE-2015-6736)MediaWiki Quiz extended Denial of Service Vulnerability (CVE-2015-6736)
Release date:Updated on: 2015-09-02Affected Systems:
MediaWiki MediaWiki MediaWiki
Description:
CVE (CAN) ID: CVE-2015-6736MediaWiki is a famous wiki program running in t
Isc bind Remote Denial of Service Vulnerability (CVE-2014-3859)
Isc bind Remote Denial of Service Vulnerability (CVE-2014-3859)
Release date:Updated on:
Affected Systems:Isc bind 9.10.0-p1Isc bind 9.10.0Description:--------------------------------------------------------------------------------Bugtraq id: 68038CVE (CAN) ID: CVE-2014-3859BIND is a widely used DNS
IBM WebSphere Portal Information Leakage Vulnerability (CVE-2014-3056)
IBM WebSphere Portal Information Leakage Vulnerability (CVE-2014-3056)
Release date:Updated on:
Affected Systems:IBM Websphere Portal 8.xDescription:--------------------------------------------------------------------------------CVE (CAN) ID: CVE
Release date:Updated on:
Affected Systems:Cisco Jabber for WindowsDescription:--------------------------------------------------------------------------------Bugtraq id: 64965CVE (CAN) ID: CVE-2014-0666
Cisco Jabber for Windows is a Unified Communication and collaborative work application.
The Send Screen Capture function of Cisco Jabber for Windows has a security vulnerability that allows unauthenticated remote attackers to install arbitrary files
Adobe Reader and Acrobat Memory Corruption Vulnerability (CVE-2016-0946)Adobe Reader and Acrobat Memory Corruption Vulnerability (CVE-2016-0946)
Release date:Updated on:Affected Systems:
Adobe Acrobat XI Adobe Acrobat Reader DC Adobe Acrobat DC
Description:
CVE (CAN) ID: CVE-2016-0946Adobe Reader is a PDF docume
The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion;
products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the
content of the page makes you feel confusing, please write us an email, we will handle the problem
within 5 days after receiving your email.
If you find any instances of plagiarism from the community, please send an email to:
info-contact@alibabacloud.com
and provide relevant evidence. A staff member will contact you within 5 working days.