Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2016-9037 | First vendor Publication | 2016-12-23 |
Vendor | Cve | Last vendor Modification | 2022-12-13 |
Security-Database Scoring CVSS v3
Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | |||
---|---|---|---|
Overall CVSS Score | 7.5 | ||
Base Score | 7.5 | Environmental Score | 7.5 |
impact SubScore | 3.6 | Temporal Score | 7.5 |
Exploitabality Sub Score | 3.9 | ||
Attack Vector | Network | Attack Complexity | Low |
Privileges Required | None | User Interaction | None |
Scope | Unchanged | Confidentiality Impact | None |
Integrity Impact | None | Availability Impact | High |
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:N/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.8 | Attack Range | Network |
Cvss Impact Score | 6.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key's value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9037 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-125 | Out-of-bounds Read |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
Snort® IPS/IDS
Date | Description |
---|---|
2017-01-19 | Tarantool xrow_header_decode out of bounds read attempt RuleID : 41080 - Revision : 2 - Type : SERVER-OTHER |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2016-12-22 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2016-2d0c8ba781.nasl - Type : ACT_GATHER_INFO |
2016-12-22 | Name : The remote Fedora host is missing one or more security updates. File : fedora_2016-badd014afe.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|---|
BID | http://www.securityfocus.com/bid/95063 |
MISC | http://www.talosintelligence.com/reports/TALOS-2016-0255/ |
Alert History
Date | Informations |
---|---|
2022-12-13 21:27:53 |
|
2022-04-20 00:23:38 |
|
2021-05-04 12:54:38 |
|
2021-04-22 02:07:18 |
|
2020-05-23 00:53:39 |
|
2019-10-10 05:19:34 |
|
2016-12-31 00:23:55 |
|
2016-12-28 09:22:17 |
|
2016-12-28 00:29:56 |
|
2016-12-24 05:33:46 |
|