CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-7649

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    2.4
    Low

    CVE-2016-7653

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Media Player" component, which allows physically proximate attackers to obtain sensitive photo and contact information by leveraging lockscreen access.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7654

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7655

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreMedia External Displays" component. It allows local users to gain privileges or cause a denial of service (type confusion) via unspecified vectors.

    Published: 20 Feb 2017
    8.8
    High

    CVE-2016-7656

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Feb 2017
    3.3
    Low

    CVE-2016-7657

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "IOKit" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7660

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2016-7661

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2016-7662

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Security" component, which allows remote attackers to spoof certificates via unspecified vectors.

    Published: 20 Feb 2017
    9.8
    Critical

    CVE-2016-7663

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "CoreFoundation" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted string.

    Published: 20 Feb 2017
    2.4
    Low

    CVE-2016-7664

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Accessibility" component. which allows physically proximate attackers to obtain sensitive photo and contact information by leveraging the availability of excessive options during lockscreen access.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2016-7667

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" component. It allows remote attackers to cause a denial of service via a crafted string.

    Published: 20 Feb 2017
    5.5
    Medium

    CVE-2016-7761

    Last Modified: 20 Apr 2025

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "WiFi" component, which allows local users to obtain sensitive network-configuration information by leveraging global storage.

    Published: 20 Feb 2017
    9.8
    Critical

    CVE-2017-12932

    Last Modified: 20 Apr 2025

    ext/standard/var_unserializer.re in PHP 7.0.x through 7.0.22 and 7.1.x through 7.1.8 is prone to a heap use after free while unserializing untrusted data, related to improper use of the hash API for key deletion in a situation with an invalid array size. Exploitation of this issue can have an unspecified impact on the integrity of PHP.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2014-9970

    Last Modified: 20 Apr 2025

    jasypt before 1.9.2 allows a timing attack against the password hash comparison.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2017-6181

    Last Modified: 20 Apr 2025

    The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted regular expression.

    Published: 20 Feb 2017
    7.5
    High

    CVE-2017-3156

    Last Modified: 20 Apr 2025

    The OAuth2 Hawk and JOSE MAC Validation code in Apache CXF prior to 3.0.13 and 3.1.x prior to 3.1.10 is not using a constant time MAC signature comparison algorithm which may be exploited by sophisticated timing attacks.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-6196

    Last Modified: 20 Apr 2025

    Multiple use-after-free vulnerabilities in the gx_image_enum_begin function in base/gxipixel.c in Ghostscript before ecceafe3abba2714ef9b432035fe0739d9b1a283 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document.

    Published: 20 Feb 2017
    8.6
    High

    CVE-2017-6413

    Last Modified: 20 Apr 2025

    The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.

    Published: 20 Feb 2017
    7.8
    High

    CVE-2017-6074

    Last Modified: 20 Apr 2025

    The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.

    Published: 18 Feb 2017
    5.5
    Medium

    CVE-2017-6502

    Last Modified: 20 Apr 2025

    An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).

    Published: 18 Feb 2017
    3.7
    Low

    CVE-2017-3533

    Last Modified: 20 Apr 2025

    Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data. Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).

    Published: 18 Feb 2017
    8.8
    High

    CVE-2017-6065

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.

    Published: 17 Feb 2017
    7.8
    High

    CVE-2017-6055

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.

    Published: 17 Feb 2017
    6.1
    Medium

    CVE-2014-9905

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Calendar in SOGo before 2.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) title of an appointment or (2) contact fields.

    Published: 17 Feb 2017
    6.1
    Medium

    CVE-2016-5364

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in manage_custom_field_edit_page.php in MantisBT 1.2.19 and earlier allows remote attackers to inject arbitrary web script or HTML via the return parameter.

    Published: 17 Feb 2017
    4.3
    Medium

    CVE-2016-6189

    Last Modified: 20 Apr 2025

    Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds.

    Published: 17 Feb 2017
    4.3
    Medium

    CVE-2016-6190

    Last Modified: 20 Apr 2025

    SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the "View the Date & Time" restriction, as demonstrated by correlating UIDs and DTSTAMPs between all users.

    Published: 17 Feb 2017
    6.1
    Medium

    CVE-2016-6191

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the View Raw Source page in the Web Calendar in SOGo before 3.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Description, (2) Location, (3) URL, or (4) Title field.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6873

    Last Modified: 20 Apr 2025

    Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6874

    Last Modified: 20 Apr 2025

    The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6875

    Last Modified: 20 Apr 2025

    Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6871

    Last Modified: 20 Apr 2025

    Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer overflow.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6872

    Last Modified: 20 Apr 2025

    Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2016-6870

    Last Modified: 20 Apr 2025

    Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

    Published: 17 Feb 2017
    4.7
    Medium

    CVE-2016-7111

    Last Modified: 20 Apr 2025

    MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 17 Feb 2017
    4.3
    Medium

    CVE-2017-5027

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to properly enforce unsafe-inline content security policy, which allowed a remote attacker to bypass content security policy via a crafted HTML page.

    Published: 17 Feb 2017
    9.8
    Critical

    CVE-2017-5344

    Last Modified: 20 Apr 2025

    An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.

    Published: 17 Feb 2017
    5.4
    Medium

    CVE-2017-5998

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name parameter in a "Web Admin Portal > Log Configuration > Add" action.

    Published: 17 Feb 2017
    5.5
    Medium

    CVE-2017-6348

    Last Modified: 20 Apr 2025

    The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.

    Published: 17 Feb 2017
    7.5
    High

    CVE-2016-5919

    Last Modified: 20 Apr 2025

    IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM Reference #: 1996868.

    Published: 16 Feb 2017
    6.1
    Medium

    CVE-2016-6062

    Last Modified: 20 Apr 2025

    IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference#: 213457065.

    Published: 16 Feb 2017
    8.8
    High

    CVE-2016-4311

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

    Published: 16 Feb 2017
    9.8
    Critical

    CVE-2016-6233

    Last Modified: 20 Apr 2025

    The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.

    Published: 16 Feb 2017
    9.1
    Critical

    CVE-2016-9814

    Last Modified: 20 Apr 2025

    The validateSignature method in the SAML2\Utils class in SimpleSAMLphp before 1.14.10 and simplesamlphp/saml2 library before 1.9.1, 1.10.x before 1.10.3, and 2.x before 2.3.3 allows remote attackers to spoof SAML responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

    Published: 16 Feb 2017
    6.3
    Medium

    CVE-2016-9955

    Last Modified: 20 Apr 2025

    The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.

    Published: 16 Feb 2017
    9.8
    Critical

    CVE-2016-10134

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.

    Published: 16 Feb 2017
    4.9
    Medium

    CVE-2016-4314

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.

    Published: 16 Feb 2017
    5.7
    Medium

    CVE-2016-4315

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

    Published: 16 Feb 2017
    6.1
    Medium

    CVE-2016-4327

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 16 Feb 2017