CVE-2016-0222 (maximo_asset_management, maximo_for_government, maximo_for_life_sciences, maximo_for_nuclear_power, maximo_for_oil_and_gas, maximo_for_transportation, maximo_for_utilities, smartcloud_control_desk)

CVE-2016-0222 (maximo_asset_management, maximo_for_government, maximo_for_life_sciences, maximo_for_nuclear_power, maximo_for_oil_and_gas, maximo_for_transportation, maximo_for_utilities, smartcloud_control_desk)

IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.

Source: CVE-2016-0222 (maximo_asset_management, maximo_for_government, maximo_for_life_sciences, maximo_for_nuclear_power, maximo_for_oil_and_gas, maximo_for_transportation, maximo_for_utilities, smartcloud_control_desk)

CVE-2016-1645

CVE-2016-1645

Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.

Source: CVE-2016-1645

CVE-2016-1644

CVE-2016-1644

WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly restrict relayout scheduling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted HTML document.

Source: CVE-2016-1644

CVE-2016-1643

CVE-2016-1643

The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly maintain the user agent shadow DOM, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

Source: CVE-2016-1643

CVE-2016-0771

CVE-2016-0771

The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

Source: CVE-2016-0771

CVE-2015-7560

CVE-2015-7560

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.

Source: CVE-2015-7560