CVE-2016-6259

CVSS v3 Score
6.2
Medium
CVSS v2 Score
4.9
Medium

Vulnerability Description

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

CVSS:6.2(Medium)

The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in font data, which allows remote attackers to cause a ...

CWE-202016
CVSS:6.2(Medium)

sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a denial of service (system crash) via a crafted ioctl ...

CWE-202016
CVSS:6.2(Medium)

sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.

CWE-202016
CVSS:6.2(Medium)

Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.

CWE-202016
CVSS:6.2(Medium)

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.

CWE-202017
CVSS:6.2(Medium)

NETGEAR R7800 devices before 1.0.2.30 are affected by incorrect configuration of security settings.

CWE-202017