CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-9600

    Last Modified: 21 Nov 2024

    JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.

    Published: 29 Dec 2016
    9.8
    Critical

    CVE-2017-5340

    Last Modified: 20 Apr 2025

    Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.

    Published: 29 Dec 2016
    7.5
    High

    CVE-2016-8741

    Last Modified: 20 Apr 2025

    The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.

    Published: 28 Dec 2016
    7.5
    High

    CVE-2016-9879

    Last Modified: 20 Apr 2025

    An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. The unexpected presence of path parameters can cause a constraint to be bypassed. Users of Apache Tomcat (all current versions) are not affected by this vulnerability since Tomcat follows the guidance previously provided by the Servlet Expert group and strips path parameters from the value returned by getContextPath(), getServletPath(), and getPathInfo(). Users of other Servlet containers based on Apache Tomcat may or may not be affected depending on whether or not the handling of path parameters has been modified. Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.

    Published: 28 Dec 2016
    5.3
    Medium

    CVE-2016-9601

    Last Modified: 21 Nov 2024

    ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image function which is used to decode halftone segments in a JBIG2 image. A document (PostScript or PDF) with an embedded, specially crafted, jbig2 image could trigger a segmentation fault in ghostscript.

    Published: 28 Dec 2016
    7.5
    High

    CVE-2016-10031

    Last Modified: 12 Apr 2025

    WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called mysqld.exe or httpd.exe and replace the original files. The next time the service starts, the malicious file will get executed as SYSTEM. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.

    Published: 27 Dec 2016
    5.3
    Medium

    CVE-2016-10072

    Last Modified: 12 Apr 2025

    WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called wampmanager.exe or unins000.exe and replace the original files. The next time one of these programs is launched by a more privileged user, malicious code chosen by the local attacker will run. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.

    Published: 27 Dec 2016
    5.5
    Medium

    CVE-2016-10217

    Last Modified: 20 Apr 2025

    The pdf14_open function in base/gdevp14.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file that is mishandled in the color management module.

    Published: 27 Dec 2016
    9.8
    Critical

    CVE-2016-7479

    Last Modified: 20 Apr 2025

    In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution.

    Published: 27 Dec 2016
    9.8
    Critical

    CVE-2016-9223

    Last Modified: 12 Apr 2025

    A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privileges on the affected system. Affected Products: This vulnerability affect all releases of Cisco CloudCenter Orchestrator (CCO) deployments where the Docker Engine TCP port 2375 is open on the system and bound to local address 0.0.0.0 (any interface).

    Published: 26 Dec 2016
    6.5
    Medium

    CVE-2016-9224

    Last Modified: 12 Apr 2025

    A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).

    Published: 26 Dec 2016
    8.8
    High

    CVE-2016-9217

    Last Modified: 12 Apr 2025

    A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. More Information: CSCus99394. Known Affected Releases: 7.3(0)ZN(0.99).

    Published: 26 Dec 2016
    5.4
    Medium

    CVE-2016-9681

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.

    Published: 25 Dec 2016
    7.5
    High

    CVE-2016-10041

    Last Modified: 12 Apr 2025

    An issue was discovered in Sprecher Automation SPRECON-E Service Program before 3.43 SP0. Under certain preconditions, it is possible to execute telegram simulation as a non-admin user. As prerequisites, a user must have created an online-connection, validly authenticated and authorized as administrator, and executed telegram simulation. After that, the online-connection must have been closed. Incorrect caching of client data then may lead to privilege escalation, where a subsequently acting non-admin user is permitted to do telegram simulation. In order to exploit this vulnerability, a potential attacker would need to have both a valid engineering-account in the SPRECON RBAC system as well as access to a service/maintenance computer with SPRECON-E Service Program running. Additionally, a valid admin-user must have closed the service connection beforehand without closing the program, having executed telegram simulation; the attacker then has access to the running software instance. Hence, there is no risk from external attackers.

    Published: 25 Dec 2016
    6.1
    Medium

    CVE-2016-10006

    Last Modified: 12 Apr 2025

    In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

    Published: 24 Dec 2016
    7.3
    High

    CVE-2016-10037

    Last Modified: 12 Apr 2025

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.

    Published: 24 Dec 2016
    7.3
    High

    CVE-2016-10038

    Last Modified: 12 Apr 2025

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.

    Published: 24 Dec 2016
    7.3
    High

    CVE-2016-10039

    Last Modified: 12 Apr 2025

    Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.

    Published: 24 Dec 2016
    9.8
    Critical

    CVE-2016-10145

    Last Modified: 20 Apr 2025

    Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.

    Published: 24 Dec 2016
    5.5
    Medium

    CVE-2016-10040

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a denial of service (application crash) via a xml file with multiple nested open tags.

    Published: 24 Dec 2016
    9.8
    Critical

    CVE-2016-10144

    Last Modified: 20 Apr 2025

    coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.

    Published: 24 Dec 2016
    4.9
    Medium

    CVE-2016-7787

    Last Modified: 12 Apr 2025

    A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.

    Published: 23 Dec 2016
    7.5
    High

    CVE-2016-9036

    Last Modified: 12 Apr 2025

    An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet can cause the mp_check function to incorrectly return success when trying to check if decoding a map16 packet will read outside the bounds of a buffer, resulting in a denial of service vulnerability.

    Published: 23 Dec 2016
    7.5
    High

    CVE-2016-9037

    Last Modified: 12 Apr 2025

    An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted packet can cause the function to access an element outside the bounds of a global array that is used to determine the type of the specified key's value. This can lead to an out of bounds read within the context of the server. An attacker who exploits this vulnerability can cause a denial of service vulnerability on the server.

    Published: 23 Dec 2016
    6.8
    Medium

    CVE-2016-2312

    Last Modified: 12 Apr 2025

    Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-6910

    Last Modified: 12 Apr 2025

    The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but the vulnerability can persist on the device even after the device has been upgraded to an Android 5.1.1 or 6.0.1 build. The vulnerable system app gives a non-existent app the ability to read the notifications from the device, which a third-party app can utilize if it uses a package name of com.samsung.android.app.portalservicewidget. This vulnerability allows an unprivileged third-party app to obtain the text of the user's notifications, which tend to contain personal data.

    Published: 23 Dec 2016
    6.1
    Medium

    CVE-2016-9889

    Last Modified: 12 Apr 2025

    Some forms with the parameter geo_zoomlevel_to_found_location in Tiki Wiki CMS 12.x before 12.10 LTS, 15.x before 15.3 LTS, and 16.x before 16.1 don't have the input sanitized, related to tiki-setup.php and article_image.php. The impact is XSS.

    Published: 23 Dec 2016
    8.1
    High

    CVE-2016-6659

    Last Modified: 12 Apr 2025

    Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.

    Published: 23 Dec 2016
    7.8
    High

    CVE-2016-6671

    Last Modified: 12 Apr 2025

    The raw_decode function in libavcodec/rawdec.c in FFmpeg before 3.1.2 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a crafted SWF file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-6881

    Last Modified: 12 Apr 2025

    The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a crafted SWF file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-7555

    Last Modified: 12 Apr 2025

    The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted "strh" structure.

    Published: 23 Dec 2016
    7.8
    High

    CVE-2016-7450

    Last Modified: 12 Apr 2025

    The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed AIFF file.

    Published: 23 Dec 2016
    7.8
    High

    CVE-2016-7502

    Last Modified: 12 Apr 2025

    The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_decode.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-7562

    Last Modified: 12 Apr 2025

    The ff_draw_pc_font function in libavcodec/cga_data.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (buffer overflow) via a crafted AVI file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-7785

    Last Modified: 12 Apr 2025

    The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-8595

    Last Modified: 12 Apr 2025

    The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-9561

    Last Modified: 12 Apr 2025

    The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of huge memory, and being killed by the OS) via a crafted MOV file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-7905

    Last Modified: 12 Apr 2025

    The read_gab2_sub function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (NULL pointer used) via a crafted AVI file.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-7122

    Last Modified: 12 Apr 2025

    The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a crafted 'nctg' structure.

    Published: 23 Dec 2016
    7.5
    High

    CVE-2016-9154

    Last Modified: 12 Apr 2025

    Siemens Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 for Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D (All firmware versions < V6.00.046) and Desigo PX Web modules PXA30-W0, PXA30-W1, PXA30-W2 for Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U (All firmware versions < V6.00.046) use a pseudo random number generator with insufficient entropy to generate certificates for HTTPS, potentially allowing remote attackers to reconstruct the corresponding private key.

    Published: 23 Dec 2016
    7.5
    High

    CVE-2017-11142

    Last Modified: 20 Apr 2025

    In PHP before 5.6.31, 7.x before 7.0.17, and 7.1.x before 7.1.3, remote attackers could cause a CPU consumption denial of service attack by injecting long form variables, related to main/php_variables.c.

    Published: 23 Dec 2016
    5.5
    Medium

    CVE-2016-10219

    Last Modified: 20 Apr 2025

    The intersect function in base/gxfill.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.

    Published: 23 Dec 2016
    9.8
    Critical

    CVE-2016-10328

    Last Modified: 20 Apr 2025

    FreeType 2 before 2016-12-16 has an out-of-bounds write caused by a heap-based buffer overflow related to the cff_parser_run function in cff/cffparse.c.

    Published: 23 Dec 2016
    6.5
    Medium

    CVE-2016-9594

    Last Modified: 15 Apr 2026

    curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that use it vulnerable.

    Published: 23 Dec 2016
    6
    Medium

    CVE-2016-10155

    Last Modified: 20 Apr 2025

    Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.

    Published: 22 Dec 2016
    7.1
    High

    CVE-2016-9599

    Last Modified: 21 Nov 2024

    puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.

    Published: 22 Dec 2016
    7.5
    High

    CVE-2016-2349

    Last Modified: 12 Apr 2025

    Remedy AR System Server in BMC Remedy 8.1 SP 2, 9.0, 9.0 SP 1, and 9.1 allows attackers to reset arbitrary passwords via a blank previous password.

    Published: 21 Dec 2016
    7.5
    High

    CVE-2016-7172

    Last Modified: 12 Apr 2025

    NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.

    Published: 21 Dec 2016
    Unknown

    CVE-2016-5103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4552. Reason: This candidate is a reservation duplicate of CVE-2016-4552. Notes: All CVE users should reference CVE-2016-4552 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Dec 2016
    6
    Medium

    CVE-2016-10024

    Last Modified: 20 Apr 2025

    Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction stream asynchronously while performing certain kernel operations.

    Published: 21 Dec 2016