CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-6789

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

    Published: 12 Jan 2017
    7
    High

    CVE-2016-8393

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31911920.

    Published: 12 Jan 2017
    7
    High

    CVE-2016-8394

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31913197.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8395

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of local permanent denial of service. Product: Android. Versions: Kernel-3.10. Android ID: A-31403040. References: N-CVE-2016-8395.

    Published: 12 Jan 2017
    5.5
    Medium

    CVE-2016-8396

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: N/A. Android ID: A-31249105.

    Published: 12 Jan 2017
    5.5
    Medium

    CVE-2016-8397

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-31385953. References: N-CVE-2016-8397.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8401

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31494725.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8402

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31495231.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8403

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31495348.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8409

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31495687. References: N-CVE-2016-8409.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8410

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the Qualcomm sound driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31498403. References: QC-CR#987010.

    Published: 12 Jan 2017
    5.5
    Medium

    CVE-2016-8400

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8405

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31651010.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8407

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31802656.

    Published: 12 Jan 2017
    4.7
    Medium

    CVE-2016-8408

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31496571. References: N-CVE-2016-8408.

    Published: 12 Jan 2017
    7.5
    High

    CVE-2017-5351

    Last Modified: 20 Apr 2025

    Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016-7650.

    Published: 12 Jan 2017
    9.8
    Critical

    CVE-2016-10131

    Last Modified: 20 Apr 2025

    system/libraries/Email.php in CodeIgniter before 3.1.3 allows remote attackers to execute arbitrary code by leveraging control over the email->from field to insert sendmail command-line arguments.

    Published: 12 Jan 2017
    7.5
    High

    CVE-2017-5350

    Last Modified: 20 Apr 2025

    Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.

    Published: 12 Jan 2017
    8.8
    High

    CVE-2017-5345

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.

    Published: 12 Jan 2017
    7.2
    High

    CVE-2017-5346

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.

    Published: 12 Jan 2017
    7.2
    High

    CVE-2017-5347

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in inc/mod/newsletter/options.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the recipient parameter to gxadmin/index.php.

    Published: 12 Jan 2017
    8.8
    High

    CVE-2017-5225

    Last Modified: 2 Mar 2026

    LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample value.

    Published: 12 Jan 2017
    7.8
    High

    CVE-2017-0381

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-31607432.

    Published: 12 Jan 2017
    6.5
    Medium

    CVE-2016-9590

    Last Modified: 21 Nov 2024

    puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

    Published: 12 Jan 2017
    8.4
    High

    CVE-2017-2583

    Last Modified: 20 Apr 2025

    The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest OS privileges via a crafted application.

    Published: 12 Jan 2017
    7.5
    High

    CVE-2017-5356

    Last Modified: 20 Apr 2025

    Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence (%[) without a closing bracket (]).

    Published: 12 Jan 2017
    7.5
    High

    CVE-2017-5357

    Last Modified: 20 Apr 2025

    regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.

    Published: 12 Jan 2017
    7.8
    High

    CVE-2017-15131

    Last Modified: 21 Nov 2024

    It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting umask policy. This only affects xdg-user-dirs before 0.15.5 as shipped with Red Hat Enterprise Linux.

    Published: 12 Jan 2017
    7.8
    High

    CVE-2017-5506

    Last Modified: 20 Apr 2025

    Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a crafted file.

    Published: 12 Jan 2017
    7.8
    High

    CVE-2017-5548

    Last Modified: 20 Apr 2025

    drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging use of more than one virtual page for a DMA scatterlist.

    Published: 12 Jan 2017
    4.8
    Medium

    CVE-2016-4807

    Last Modified: 20 Apr 2025

    Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).

    Published: 11 Jan 2017
    3.7
    Low

    CVE-2016-9015

    Last Modified: 20 Apr 2025

    Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.

    Published: 11 Jan 2017
    3.7
    Low

    CVE-2015-8020

    Last Modified: 20 Apr 2025

    Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-4806

    Last Modified: 20 Apr 2025

    Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

    Published: 11 Jan 2017
    8.8
    High

    CVE-2016-4808

    Last Modified: 20 Apr 2025

    Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.

    Published: 11 Jan 2017
    7.5
    High

    CVE-2016-6820

    Last Modified: 20 Apr 2025

    MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauthenticated user.

    Published: 11 Jan 2017
    9.1
    Critical

    CVE-2017-5209

    Last Modified: 20 Apr 2025

    The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2943

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing tags in TIFF images. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2952

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow / underflow vulnerability in the image conversion module related to parsing tags in TIFF files. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2967

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the XFA engine related to a form's structure and organization. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2942

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability when processing TIFF image data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2939

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing a malformed cross-reference table. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2940

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing JPEG 2000 files. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2941

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability when processing Compact Font Format data. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2945

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability when parsing TIFF image files. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2946

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable heap overflow vulnerability when parsing the segment for storing non-graphic information. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    5.5
    Medium

    CVE-2017-2947

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manipulating Form Data Format (FDF).

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2948

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow / underflow vulnerability in the XFA engine. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2951

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable use after free vulnerability in the XFA engine, related to sub-form functionality. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017
    7.8
    High

    CVE-2017-2953

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when processing a TIFF image. Successful exploitation could lead to arbitrary code execution.

    Published: 11 Jan 2017