SCAP Feed Release : 23-Sep-2016

  • Post author:
  • Reading time:64 mins read

The following SCAP content has been released to SCAP Repo and SecPod ANCOR. SecPod Saner will automatically pull the relevant content on its next scheduled update.

oval:org.secpod.oval:def:37380 CVE-2016-6304 Denial of service vulnerability in the OCSP Status Request extension in OpenSSL via a malicious client
oval:org.secpod.oval:def:37381 CVE-2016-6305 Denial of service vulnerability in OpenSSL via a malicious peer
oval:org.secpod.oval:def:37382 CVE-2016-6306 Denial of service vulnerability in OpenSSL via message length checks
oval:org.secpod.oval:def:37383 CVE-2016-6307 Denial of service vulnerability in OpenSSL via a TLS message
oval:org.secpod.oval:def:37384 CVE-2016-6308 Denial of service vulnerability in OpenSSL via a DTLS message
oval:org.secpod.oval:def:37377 CVE-2016-7081 Heap-based buffer overflow vulnerability in VMware Workstation and VMware Player via a Cortado ThinPrint – CVE-2016-7081
oval:org.secpod.oval:def:37376 CVE-2016-7082 Memory corruption vulnerability in VMware Workstation and VMware Player via a Cortado ThinPrint – CVE-2016-7082
oval:org.secpod.oval:def:37375 CVE-2016-7083 Memory corruption vulnerability in VMware Workstation and VMware Player via a Cortado ThinPrint – CVE-2016-7083
oval:org.secpod.oval:def:37374 CVE-2016-7084 Memory corruption vulnerability in VMware Workstation and VMware Player via a Cortado ThinPrint – CVE-2016-7084
oval:org.secpod.oval:def:37373 CVE-2016-7085 DLL hijack vulnerability in VMware Workstation and VMware Player via DLL files – CVE-2016-7085
oval:org.secpod.oval:def:37372 CVE-2016-7086 Insecure executable loading vulnerability in VMware Workstation and VMware Player – CVE-2016-7086
oval:org.secpod.oval:def:37284 CVE-2016-2827 Out-of-bounds read vulnerability in mozilla::net::IsValidReferrerPolicy in Mozilla Firefox (MAC OS X)
oval:org.secpod.oval:def:37293 CVE-2016-5279 Information disclosure vulnerability in Mozilla Firefox while using drag and drop (MAC OS X)
oval:org.secpod.oval:def:37294 CVE-2016-5280 Use-after-free vulnerability in mozilla::nsTextNodeDirectionalityMap:: RemoveElementFromMap in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37295 CVE-2016-5281 Use-after-free vulnerability in DOMSVGLength in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37296 CVE-2016-5282 Privilege escalation vulnerability in Mozilla Firefox while requesting favicons from non-whitelisted schemes (MAC OS X)
oval:org.secpod.oval:def:37297 CVE-2016-5283 Cross origin data disclosure vulnerability in Mozilla Firefox via fragment timing attack (MAC OS X)
oval:org.secpod.oval:def:37298 CVE-2016-5284 Malicious add-on injection vulnerability in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37299 CVE-2016-5256 Memory corruption vulnerability in Mozilla Firefox – CVE-2016-5256 (MAC OS X)
oval:org.secpod.oval:def:37302 CVE-2016-5250 Information disclosure vulnerability in Resource Timing API in Mozilla Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37303 CVE-2016-5261 Integer overflow vulnerability in WebSocketChannel in Mozilla Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37301 CVE-2016-5257 Memory corruption vulnerability in Mozilla Firefox or Firefox ESR – CVE-2016-5257 (MAC OS X)
oval:org.secpod.oval:def:37304 CVE-2016-2827
CVE-2016-5256
CVE-2016-5257
CVE-2016-5270
CVE-2016-5271
CVE-2016-5272
CVE-2016-5273
CVE-2016-5274
CVE-2016-5275
CVE-2016-5276
CVE-2016-5277
CVE-2016-5278
CVE-2016-5279
CVE-2016-5280
CVE-2016-5281
CVE-2016-5282
CVE-2016-5283
CVE-2016-5284
MFSA2016-85
Multiple vulnerabilities in Mozilla Firefox – MFSA2016-85 (MAC OS X)
oval:org.secpod.oval:def:37305 CVE-2016-5250
CVE-2016-5257
CVE-2016-5261
CVE-2016-5270
CVE-2016-5272
CVE-2016-5274
CVE-2016-5276
CVE-2016-5277
CVE-2016-5278
CVE-2016-5280
CVE-2016-5281
CVE-2016-5284
MFSA2016-86
Multiple vulnerabilities in Mozilla Firefox ESR – MFSA2016-86 (MAC OS X)
oval:org.secpod.oval:def:37300 CVE-2016-5275 Global buffer overflow vulnerability in mozilla::gfx::FilterSupport::ComputeSourceNeededRegions in Mozilla Firefox (MAC OS X)
oval:org.secpod.oval:def:37285 CVE-2016-5270 Heap based buffer overflow vulnerability in nsCaseTransformTextRunFactory::TransformString in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37286 CVE-2016-5271 Out-of-bounds vulnerability in PropertyProvider::GetSpacingInternal in Mozilla Firefox (MAC OS X)
oval:org.secpod.oval:def:37287 CVE-2016-5272 Denial of service vulnerability in Mozilla Firefox and Firefox ESR due to a bad cast in nsImageGeometryMixin (MAC OS X)
oval:org.secpod.oval:def:37288 CVE-2016-5273 Denial of service vulnerability in mozilla::a11y::HyperTextAccessible::GetChildOffset in Mozilla Firefox (MAC OS X)
oval:org.secpod.oval:def:37289 CVE-2016-5276 Heap-use-after-free vulnerability in mozilla::a11y::DocAccessible::ProcessInvalidationList in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37290 CVE-2016-5274 Use-after-free vulnerability in web animations in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37291 CVE-2016-5277 Heap-use-after-free vulnerability in nsRefreshDriver::Tick in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37292 CVE-2016-5278 Heap-buffer-overflow vulnerability in nsBMPEncoder::AddImageFrame in Mozilla Firefox and Firefox ESR (MAC OS X)
oval:org.secpod.oval:def:37306 APPLE-SA-2016-09-20
CVE-2016-0755
CVE-2016-4658
CVE-2016-4694
CVE-2016-4696
CVE-2016-4697
CVE-2016-4698
CVE-2016-4699
CVE-2016-4700
CVE-2016-4701
CVE-2016-4702
CVE-2016-4703
CVE-2016-4706
CVE-2016-4707
CVE-2016-4708
CVE-2016-4709
CVE-2016-4710
CVE-2016-4711
CVE-2016-4712
CVE-2016-4713
CVE-2016-4715
CVE-2016-4716
CVE-2016-4717
CVE-2016-4718
CVE-2016-4722
CVE-2016-4723
CVE-2016-4724
CVE-2016-4725
CVE-2016-4726
CVE-2016-4727
CVE-2016-4736
CVE-2016-4738
CVE-2016-4739
CVE-2016-4742
CVE-2016-4745
CVE-2016-4748
CVE-2016-4750
CVE-2016-4752
CVE-2016-4753
CVE-2016-4755
CVE-2016-4771
CVE-2016-4772
CVE-2016-4773
CVE-2016-4774
CVE-2016-4775
CVE-2016-4776
CVE-2016-4777
CVE-2016-4778
CVE-2016-4779
CVE-2016-5131
CVE-2016-5768
CVE-2016-5769
CVE-2016-5770
CVE-2016-5771
CVE-2016-5772
CVE-2016-5773
CVE-2016-6174
CVE-2016-6288
CVE-2016-6289
CVE-2016-6290
CVE-2016-6291
CVE-2016-6292
CVE-2016-6294
CVE-2016-6295
CVE-2016-6296
CVE-2016-6297
Multiple vulnerabilities in Apple Mac OS X – APPLE-SA-2016-09-20
oval:org.secpod.oval:def:37308 CVE-2016-4658 Memory corruption vulnerability in libxml2 in Apple Mac OS X – CVE-2016-4658
oval:org.secpod.oval:def:37309 CVE-2016-4694 Arbitrary code execution vulnerability in apache in Apple Mac OS X – CVE-2016-4694
oval:org.secpod.oval:def:37310 CVE-2016-4696 Null pointer dereference vulnerability in AppleEFIRuntime in Apple Mac OS X – CVE-2016-4696
oval:org.secpod.oval:def:37311 CVE-2016-4697 Memory corruption vulnerability in Apple HSSPI Support in Apple Mac OS X – CVE-2016-4697
oval:org.secpod.oval:def:37312 CVE-2016-4698 Arbitrary code execution vulnerability in AppleMobileFileIntegrity in Apple Mac OS X – CVE-2016-4698
oval:org.secpod.oval:def:37313 CVE-2016-4699 Memory corruption vulnerability in AppleUUC in Apple Mac OS X – CVE-2016-4699
oval:org.secpod.oval:def:37314 CVE-2016-4700 Memory corruption vulnerability in AppleUUC in Apple Mac OS X – CVE-2016-4700
oval:org.secpod.oval:def:37315 CVE-2016-4701 Denial of service vulnerability in the application Firewall in Apple Mac OS X – CVE-2016-4701
oval:org.secpod.oval:def:37316 CVE-2016-4702 Memory corruption vulnerability in Audio in Apple Mac OS X – CVE-2016-4702
oval:org.secpod.oval:def:37317 CVE-2016-4703 Memory corruption vulnerability in Bluetooth in Apple Mac OS X – CVE-2016-4703
oval:org.secpod.oval:def:37318 CVE-2016-4706 Denial of service vulnerability in cd9660 in Apple Mac OS X – CVE-2016-4706
oval:org.secpod.oval:def:37319 CVE-2016-4707 Information disclosure vulnerability in CFNetwork in Apple Mac OS X – CVE-2016-4707
oval:org.secpod.oval:def:37320 CVE-2016-4708 Information disclosure vulnerability in CFNetwork in Apple Mac OS X – CVE-2016-4708
oval:org.secpod.oval:def:37321 CVE-2016-4709 Type confusion vulnerability in WindowServer in Apple Mac OS X – CVE-2016-4709
oval:org.secpod.oval:def:37322 CVE-2016-4710 Type confusion vulnerability in WindowServer in Apple Mac OS X – CVE-2016-4710
oval:org.secpod.oval:def:37323 CVE-2016-4711 Information disclosure vulnerability in CommonCrypto in Apple Mac OS X – CVE-2016-4711
oval:org.secpod.oval:def:37324 CVE-2016-4712 Out-of-bounds write vulnerability in CoreCrypto in Apple Mac OS X – CVE-2016-4712
oval:org.secpod.oval:def:37325 CVE-2016-4713 Privilege escalation vulnerability in CoreDisplay in Apple Mac OS X – CVE-2016-4713
oval:org.secpod.oval:def:37326 CVE-2016-4715 Information disclosure vulnerability in Date and Time Pref Pane in Apple Mac OS X – CVE-2016-4715
oval:org.secpod.oval:def:37327 CVE-2016-4716 Arbitrary code execution vulnerability in DiskArbitration in Apple Mac OS X – CVE-2016-4716
oval:org.secpod.oval:def:37328 CVE-2016-4717 Denial of service vulnerability in File Bookmark in Apple Mac OS X – CVE-2016-4717
oval:org.secpod.oval:def:37329 CVE-2016-4718 Buffer overflow vulnerability in FontParser in Apple Mac OS X – CVE-2016-4718
oval:org.secpod.oval:def:37330 CVE-2016-4722 Spoofing vulnerability in IDS – Connectivity in Apple Mac OS X – CVE-2016-4722
oval:org.secpod.oval:def:37331 CVE-2016-4723 Memory corruption vulnerability in Intel Graphics Driver in Apple Mac OS X – CVE-2016-4723
oval:org.secpod.oval:def:37332 CVE-2016-4724 NULL pointer dereference vulnerability in IOAcceleratorFamily in Apple Mac OS X – CVE-2016-4724
oval:org.secpod.oval:def:37333 CVE-2016-4725 Memory corruption vulnerability in IOAcceleratorFamily in Apple Mac OS X – CVE-2016-4725
oval:org.secpod.oval:def:37334 CVE-2016-4726 Memory corruption vulnerability in IOAcceleratorFamily in Apple Mac OS X – CVE-2016-4726
oval:org.secpod.oval:def:37335 CVE-2016-4727 Memory corruption vulnerability in IOThunderboltFamily in Apple Mac OS X – CVE-2016-4727
oval:org.secpod.oval:def:37336 CVE-2016-4736 Multiple memory corruption vulnerabilities in libarchive in Apple Mac OS X – CVE-2016-4736
oval:org.secpod.oval:def:37337 CVE-2016-4738 Memory corruption vulnerability in libxslt in Apple Mac OS X – CVE-2016-4738
oval:org.secpod.oval:def:37338 CVE-2016-4739 Information disclosure vulnerability in mDNSResponder in Apple Mac OS X – CVE-2016-4739
oval:org.secpod.oval:def:37339 CVE-2016-4742 Privilege escalation vulnerability in NSSecureTextField in Apple Mac OS X – CVE-2016-4742
oval:org.secpod.oval:def:37340 CVE-2016-4745 Information disclosure vulnerability in Kerberos v5 PAM module in Apple Mac OS X – CVE-2016-4745
oval:org.secpod.oval:def:37341 CVE-2016-4748 Security feature bypass vulnerability in in Apple Mac OS X – CVE-2016-4748
oval:org.secpod.oval:def:37342 CVE-2016-4750 Memory corruption vulnerability in S2 Camera in Apple Mac OS X – CVE-2016-4750
oval:org.secpod.oval:def:37343 CVE-2016-4752 Memory corruption vulnerability in Security in Apple Mac OS X – CVE-2016-4752
oval:org.secpod.oval:def:37344 CVE-2016-4753 Privilege escalation vulnerability in Security in Apple Mac OS X – CVE-2016-4753
oval:org.secpod.oval:def:37345 CVE-2016-4755 Information disclosure vulnerability in Terminal in Apple Mac OS X – CVE-2016-4755
oval:org.secpod.oval:def:37346 CVE-2016-4771 Privilege escalation vulnerability in Kernel in Apple Mac OS X – CVE-2016-4771
oval:org.secpod.oval:def:37347 CVE-2016-4772 Denial of service vulnerability in Kernel in Apple Mac OS X – CVE-2016-4772
oval:org.secpod.oval:def:37348 CVE-2016-4773 Out of bounds read vulnerability in Kernel in Apple Mac OS X – CVE-2016-4773
oval:org.secpod.oval:def:37349 CVE-2016-4774 Out of bounds read vulnerability in Kernel in Apple Mac OS X – CVE-2016-4774
oval:org.secpod.oval:def:37350 CVE-2016-4775 Memory corruption vulnerability in Kernel in Apple Mac OS X – CVE-2016-4775
oval:org.secpod.oval:def:37351 CVE-2016-4776 Out of bounds read vulnerability in Kernel in Apple Mac OS X – CVE-2016-4776
oval:org.secpod.oval:def:37352 CVE-2016-4777 Untrusted pointer dereference vulnerability in Kernel in Apple Mac OS X – CVE-2016-4777
oval:org.secpod.oval:def:37353 CVE-2016-4778 Multiple memory corruption vulnerabilities in in Apple Mac OS X – CVE-2016-4778
oval:org.secpod.oval:def:37354 CVE-2016-4779 Memory corruption vulnerability in ATS in Apple Mac OS X – CVE-2016-4779
oval:org.secpod.oval:def:37355 CVE-2016-5131 Memory corruption vulnerability in libxml2 in Apple Mac OS X – CVE-2016-5131
oval:org.secpod.oval:def:37356 CVE-2016-5768 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5768
oval:org.secpod.oval:def:37357 CVE-2016-5769 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5769
oval:org.secpod.oval:def:37358 CVE-2016-5770 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5770
oval:org.secpod.oval:def:37359 CVE-2016-5771 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5771
oval:org.secpod.oval:def:37360 CVE-2016-5772 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5772
oval:org.secpod.oval:def:37361 CVE-2016-5773 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-5773
oval:org.secpod.oval:def:37362 CVE-2016-6174 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6174
oval:org.secpod.oval:def:37363 CVE-2016-6288 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6288
oval:org.secpod.oval:def:37364 CVE-2016-6289 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6289
oval:org.secpod.oval:def:37365 CVE-2016-6290 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6290
oval:org.secpod.oval:def:37366 CVE-2016-6291 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6291
oval:org.secpod.oval:def:37367 CVE-2016-6292 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6292
oval:org.secpod.oval:def:37368 CVE-2016-6294 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6294
oval:org.secpod.oval:def:37369 CVE-2016-6295 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6295
oval:org.secpod.oval:def:37370 CVE-2016-6296 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6296
oval:org.secpod.oval:def:37371 CVE-2016-6297 Arbitrary code execution vulnerability in apache_mod_php in Apple Mac OS X – CVE-2016-6297
oval:org.secpod.oval:def:37307 CVE-2016-0755 Multiple security information disclosure vulnerability in curl in Apple Mac OS X – CVE-2016-0755
oval:org.secpod.oval:def:501873 CVE-2016-5250
CVE-2016-5257
CVE-2016-5261
CVE-2016-5270
CVE-2016-5272
CVE-2016-5274
CVE-2016-5276
CVE-2016-5277
CVE-2016-5278
CVE-2016-5280
CVE-2016-5281
CVE-2016-5284
RHSA-2016:1912-01
RHSA-2016:1912-01 — Redhat firefox
oval:org.secpod.oval:def:602620 CVE-2016-7044
CVE-2016-7045
DSA-3672-1
DSA-3672-1 irssi — irssi
oval:org.secpod.oval:def:602621 CVE-2016-2177
CVE-2016-2178
CVE-2016-2179
CVE-2016-2180
CVE-2016-2181
CVE-2016-2182
CVE-2016-2183
CVE-2016-6302
CVE-2016-6303
CVE-2016-6304
CVE-2016-6306
DSA-3673-1
DSA-3673-1 openssl — openssl
oval:org.secpod.oval:def:602622 CVE-2016-5250
CVE-2016-5257
CVE-2016-5261
CVE-2016-5270
CVE-2016-5272
CVE-2016-5274
CVE-2016-5276
CVE-2016-5277
CVE-2016-5278
CVE-2016-5280
CVE-2016-5281
CVE-2016-5284
DSA-3674-1
DSA-3674-1 firefox-esr — firefox-esr
oval:org.secpod.oval:def:703277 CVE-2016-6352
USN-3085-1
USN-3085-1 — gdk-pixbuf vulnerabilities
oval:org.secpod.oval:def:703278 CVE-2016-2827
CVE-2016-5256
CVE-2016-5257
CVE-2016-5270
CVE-2016-5271
CVE-2016-5272
CVE-2016-5273
CVE-2016-5274
CVE-2016-5275
CVE-2016-5276
CVE-2016-5277
CVE-2016-5278
CVE-2016-5279
CVE-2016-5280
CVE-2016-5281
CVE-2016-5282
CVE-2016-5283
CVE-2016-5284
USN-3076-1
USN-3076-1 — firefox vulnerabilities
oval:org.secpod.oval:def:703279 CVE-2016-2836
USN-3073-1
USN-3073-1 — thunderbird vulnerabilities
oval:org.secpod.oval:def:703280 CVE-2016-2178
CVE-2016-2179
CVE-2016-2180
CVE-2016-2181
CVE-2016-2182
CVE-2016-2183
CVE-2016-6302
CVE-2016-6303
CVE-2016-6304
CVE-2016-6306
USN-3087-1
USN-3087-1 — openssl vulnerabilities
oval:org.secpod.oval:def:703281 CVE-2016-7044
CVE-2016-7045
USN-3086-1
USN-3086-1 — irssi vulnerabilities
oval:org.secpod.oval:def:1600452 ALAS-2016-749
CVE-2016-6304
CVE-2016-6305
ALAS-2016-749 —- openssl
oval:org.secpod.oval:def:204002 CESA-2016:1847
CVE-2016-3134
CVE-2016-4997
CVE-2016-4998
CESA-2016:1847 — centos 7 kernel,python-perf,perf
oval:org.secpod.oval:def:703267 CVE-2016-3857
USN-3082-1
USN-3082-1 — linux-image
oval:org.secpod.oval:def:703268 CVE-2015-8767
CVE-2016-3841
USN-3083-2
USN-3083-2 — linux-image
oval:org.secpod.oval:def:703269 CVE-2015-8767
CVE-2016-3841
USN-3083-1
USN-3083-1 — linux-image
oval:org.secpod.oval:def:703270 CVE-2016-1240
USN-3081-1
USN-3081-1 — tomcat vulnerability
oval:org.secpod.oval:def:703271 CVE-2016-3857
USN-3082-2
USN-3082-2 — linux-image
oval:org.secpod.oval:def:703272 CVE-2016-5412
CVE-2016-6136
CVE-2016-6156
USN-3084-2
USN-3084-2 — linux-image
oval:org.secpod.oval:def:703273 CVE-2016-5412
CVE-2016-6136
CVE-2016-6156
USN-3084-3
USN-3084-3 — linux-image
oval:org.secpod.oval:def:703274 CVE-2016-5412
CVE-2016-6136
CVE-2016-6156
USN-3084-1
USN-3084-1 — linux-image
oval:org.secpod.oval:def:703275 CVE-2016-5412
CVE-2016-6136
CVE-2016-6156
USN-3084-4
USN-3084-4 — linux-image
oval:org.secpod.oval:def:602619 CVE-2016-7176
CVE-2016-7177
CVE-2016-7178
CVE-2016-7179
CVE-2016-7180
DSA-3671-1
DSA-3671-1 wireshark — wireshark