ALT-BU-2016-2583-1
Branch t7 update bulletin.
Package adobe-flash-player updated to version 11-alt59 for branch t7 in task 158831.
Closed vulnerabilities
Modified: 2021-03-23
BDU:2016-00414
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2025-02-06
BDU:2016-00457
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00458
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00459
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00460
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00461
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00462
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00463
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00464
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00465
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00466
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00467
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00468
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00469
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00470
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00471
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00472
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00473
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00474
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00475
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00476
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код
Modified: 2021-03-23
BDU:2016-00537
Уязвимость программных платформ Adobe Integrated Runtime и Flash Player, позволяющая нарушителю выполнить произвольный код
Modified: 2025-04-12
CVE-2016-0964
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39467/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39467/
Modified: 2025-04-12
CVE-2016-0965
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39460/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39460/
Modified: 2025-04-12
CVE-2016-0966
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0967
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39466/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39466/
Modified: 2025-04-12
CVE-2016-0968
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0969
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0970
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0971
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39465/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39465/
Modified: 2025-04-12
CVE-2016-0972
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0973
Use-after-free vulnerability in the URLRequest object implementation in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via a URLLoader.load call, a different vulnerability than CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- http://zerodayinitiative.com/advisories/ZDI-16-161/
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- http://zerodayinitiative.com/advisories/ZDI-16-161/
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0974
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0975, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39463/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39463/
Modified: 2025-04-12
CVE-2016-0975
Use-after-free vulnerability in the instanceof function in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code by leveraging improper reference handling, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0982, CVE-2016-0983, and CVE-2016-0984.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- http://zerodayinitiative.com/advisories/ZDI-16-160/
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- http://zerodayinitiative.com/advisories/ZDI-16-160/
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0976
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0977
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0978, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0978
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0979, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0979
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0980, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0980
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, and CVE-2016-0981.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0981
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0964, CVE-2016-0965, CVE-2016-0966, CVE-2016-0967, CVE-2016-0968, CVE-2016-0969, CVE-2016-0970, CVE-2016-0972, CVE-2016-0976, CVE-2016-0977, CVE-2016-0978, CVE-2016-0979, and CVE-2016-0980.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0982
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0983, and CVE-2016-0984.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-04-12
CVE-2016-0983
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0984.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
Modified: 2025-10-22
CVE-2016-0984
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0973, CVE-2016-0974, CVE-2016-0975, CVE-2016-0982, and CVE-2016-0983.
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39462/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39462/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0984
Modified: 2025-04-12
CVE-2016-0985
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execute arbitrary code by leveraging an unspecified "type confusion."
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39461/
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00029.html
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00030.html
- http://rhn.redhat.com/errata/RHSA-2016-0166.html
- http://www.securitytracker.com/id/1034970
- https://helpx.adobe.com/security/products/flash-player/apsb16-04.html
- https://security.gentoo.org/glsa/201603-07
- https://www.exploit-db.com/exploits/39461/
Closed vulnerabilities
Modified: 2016-11-28
BDU:2015-00638
Уязвимость программного обеспечения nginx, позволяющая удаленному злоумышленнику нарушить конфиденциальность защищаемой информации
Modified: 2021-03-23
BDU:2016-00707
Уязвимость прокси-сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2025-04-12
CVE-2014-3556
The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place, related to a "plaintext command injection" attack, a similar issue to CVE-2011-0411.
- http://mailman.nginx.org/pipermail/nginx-announce/2014/000144.html
- http://marc.info/?l=bugtraq&m=142103967620673&w=2
- http://nginx.org/download/patch.2014.starttls.txt
- https://bugzilla.redhat.com/show_bug.cgi?id=1126891
- http://mailman.nginx.org/pipermail/nginx-announce/2014/000144.html
- http://marc.info/?l=bugtraq&m=142103967620673&w=2
- http://nginx.org/download/patch.2014.starttls.txt
- https://bugzilla.redhat.com/show_bug.cgi?id=1126891
Modified: 2025-04-12
CVE-2014-3616
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct "virtual host confusion" attacks.
Modified: 2025-04-12
CVE-2016-0742
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302587
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302587
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
Modified: 2025-04-12
CVE-2016-0746
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302588
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302588
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
Modified: 2025-04-12
CVE-2016-0747
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302589
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302589
- https://security.gentoo.org/glsa/201606-06
- https://support.apple.com/kb/HT212818
Closed bugs
Критические уязвимости в коде resolver