CVE-2016-2946
published 2016-12-01CVE-2016-2946: Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on…
PriorityP337high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
32.8th percentile
Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9904 Mozilla: Cross-origin information leak in shared atoms (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 7.5
CVE-2016-9904 [HIGH] CVE-2016-9904 Mozilla: Cross-origin information leak in shared atoms (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9904 Mozilla: Cross-origin information leak in shared atoms (MFSA 2016-94, MFSA 2016-95)
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9904
Acknowledgements:
Name: the Mozilla project
Upstream: Jann Horn
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
Bugzilla
CVE-2016-9898 Mozilla: Use-after-free in Editor while manipulating DOM subtrees (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 9.8
CVE-2016-9898 [CRITICAL] CVE-2016-9898 Mozilla: Use-after-free in Editor while manipulating DOM subtrees (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9898 Mozilla: Use-after-free in Editor while manipulating DOM subtrees (MFSA 2016-94, MFSA 2016-95)
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9898
Acknowledgements:
Name: the Mozilla project
Upstream: Nils
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
Bugzilla
CVE-2016-9895 Mozilla: CSP bypass using marquee tag (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 6.1
CVE-2016-9895 [MEDIUM] CVE-2016-9895 Mozilla: CSP bypass using marquee tag (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9895 Mozilla: CSP bypass using marquee tag (MFSA 2016-94, MFSA 2016-95)
Event handlers on marquee elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9895
Acknowledgements:
Name: the Mozilla project
Upstream: Andrew Krasichkov
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2973 https://rhn.redhat.com/erra
Bugzilla
CVE-2016-9901 Mozilla: Data from Pocket server improperly sanitized before execution (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 9.8
CVE-2016-9901 [CRITICAL] CVE-2016-9901 Mozilla: Data from Pocket server improperly sanitized before execution (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9901 Mozilla: Data from Pocket server improperly sanitized before execution (MFSA 2016-94, MFSA 2016-95)
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the about:pocket-saved (unprivileged) page, giving it access to Pocket's messaging API through HTML injection.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9901
Acknowledgements:
Name: the Mozilla project
Upstream: Wladimir Palant
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the following
Bugzilla
CVE-2016-9905 Mozilla: Crash in EnumerateSubDocuments (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 8.8
CVE-2016-9905 [HIGH] CVE-2016-9905 Mozilla: Crash in EnumerateSubDocuments (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9905 Mozilla: Crash in EnumerateSubDocuments (MFSA 2016-94, MFSA 2016-95)
A potentially exploitable crash in EnumerateSubDocuments while adding or removing sub-documents.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9905
Acknowledgements:
Name: the Mozilla project
Upstream: Philipp
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2973 https://rhn.redhat.com/errata/RHSA-2016-2973.html
Bugzilla
CVE-2016-9897 Mozilla: Memory corruption in libGLES (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 7.5
CVE-2016-9897 [HIGH] CVE-2016-9897 Mozilla: Memory corruption in libGLES (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9897 Mozilla: Memory corruption in libGLES (MFSA 2016-94, MFSA 2016-95)
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9897
Acknowledgements:
Name: the Mozilla project
Upstream: Aral
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
Bugzilla
CVE-2016-9899 Mozilla: Use-after-free while manipulating DOM events and audio elements (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 9.8
CVE-2016-9899 [CRITICAL] CVE-2016-9899 Mozilla: Use-after-free while manipulating DOM events and audio elements (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9899 Mozilla: Use-after-free while manipulating DOM events and audio elements (MFSA 2016-94, MFSA 2016-95)
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2016-95/#CVE-2016-9899
Acknowledgements:
Name: the Mozilla project
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2973 https://rhn.redhat.com/erra
Bugzilla
CVE-2016-9900 Mozilla: Restricted external resources can be loaded by SVG images through data URLs (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 7.5
CVE-2016-9900 [HIGH] CVE-2016-9900 Mozilla: Restricted external resources can be loaded by SVG images through data URLs (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9900 Mozilla: Restricted external resources can be loaded by SVG images through data URLs (MFSA 2016-94, MFSA 2016-95)
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of data: URLs. This could allow for cross-domain data leakage.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9900
Acknowledgements:
Name: the Mozilla project
Upstream: insertscript
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat En
Bugzilla
CVE-2016-9902 Mozilla: Pocket extension does not validate the origin of events (MFSA 2016-94, MFSA 2016-95)
bugzilla·2016-12-13·CVSS 7.5
CVE-2016-9902 [HIGH] CVE-2016-9902 Mozilla: Pocket extension does not validate the origin of events (MFSA 2016-94, MFSA 2016-95)
CVE-2016-9902 Mozilla: Pocket extension does not validate the origin of events (MFSA 2016-94, MFSA 2016-95)
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context.
External Reference:
https://www.mozilla.org/security/announce/2016/mfsa2016-95/#CVE-2016-9902
Acknowledgements:
Name: the Mozilla project
Upstream: Wladimir Palant
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2016:2946 https://rhn.redhat.com/errata/RHSA-2016-2946.html
---
This issue has been addressed in the follo
http://www-01.ibm.com/support/docview.wss?uid=swg1IV85845http://www-01.ibm.com/support/docview.wss?uid=swg21984578http://www.securityfocus.com/bid/92389http://www-01.ibm.com/support/docview.wss?uid=swg1IV85845http://www-01.ibm.com/support/docview.wss?uid=swg21984578http://www.securityfocus.com/bid/92389
2016-12-01
Published