CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-0736

    Last Modified: 20 Apr 2025

    In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. This made it vulnerable to padding oracle attacks, particularly with CBC.

    Published: 20 Dec 2016
    9.8
    Critical

    CVE-2016-9877

    Last Modified: 12 Apr 2025

    An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a username/password pair succeeds if an existing username is provided but the password is omitted from the connection request. Connections that use TLS with a client-provided certificate are not affected.

    Published: 20 Dec 2016
    5.5
    Medium

    CVE-2016-10170

    Last Modified: 20 Apr 2025

    The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

    Published: 20 Dec 2016
    7.8
    High

    CVE-2016-10094

    Last Modified: 20 Apr 2025

    Off-by-one error in the t2p_readwrite_pdf_image_tile function in tools/tiff2pdf.c in LibTIFF 4.0.7 allows remote attackers to have unspecified impact via a crafted image.

    Published: 20 Dec 2016
    5.5
    Medium

    CVE-2016-10171

    Last Modified: 20 Apr 2025

    The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

    Published: 20 Dec 2016
    5.5
    Medium

    CVE-2016-10172

    Last Modified: 20 Apr 2025

    The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

    Published: 20 Dec 2016
    7.5
    High

    CVE-2016-2161

    Last Modified: 20 Apr 2025

    In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to crash even for subsequently valid requests.

    Published: 20 Dec 2016
    4.7
    Medium

    CVE-2016-9593

    Last Modified: 21 Nov 2024

    foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.

    Published: 20 Dec 2016
    7.5
    High

    CVE-2016-8743

    Last Modified: 20 Apr 2025

    Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers, either through mod_proxy or using conventional CGI mechanisms, and may result in request smuggling, response splitting and cache pollution.

    Published: 20 Dec 2016
    9.8
    Critical

    CVE-2016-2355

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the REST API in dotCMS before 3.3.2 allows remote attackers to execute arbitrary SQL commands via the stName parameter to api/content/save/1.

    Published: 19 Dec 2016
    7.5
    High

    CVE-2016-10005

    Last Modified: 12 Apr 2025

    Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~timeoff~wd requests, aka SAP Security Note 2344524.

    Published: 19 Dec 2016
    7.8
    High

    CVE-2016-10012

    Last Modified: 29 May 2026

    The shared memory manager (associated with pre-authentication compression) in sshd in OpenSSH before 7.4 does not ensure that a bounds check is enforced by all compilers, which might allows local users to gain privileges by leveraging access to a sandboxed privilege-separation process, related to the m_zback and m_zlib data structures.

    Published: 19 Dec 2016
    6.2
    Medium

    CVE-2016-10011

    Last Modified: 29 May 2026

    authfile.c in sshd in OpenSSH before 7.4 does not properly consider the effects of realloc on buffer contents, which might allow local users to obtain sensitive private-key information by leveraging access to a privilege-separated child process.

    Published: 19 Dec 2016
    7
    High

    CVE-2016-10010

    Last Modified: 29 May 2026

    sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.

    Published: 19 Dec 2016
    7.3
    High

    CVE-2016-10009

    Last Modified: 29 May 2026

    Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.

    Published: 19 Dec 2016
    6.5
    Medium

    CVE-2016-2125

    Last Modified: 21 Nov 2024

    It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to which Samba authenticated using Kerberos could subsequently use the ticket to impersonate Samba to other services or domain users.

    Published: 19 Dec 2016
    5.5
    Medium

    CVE-2016-10218

    Last Modified: 20 Apr 2025

    The pdf14_pop_transparency_group function in base/gdevp14.c in the PDF Transparency module in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

    Published: 19 Dec 2016
    6.5
    Medium

    CVE-2016-2126

    Last Modified: 20 Apr 2025

    Samba version 4.0.0 up to 4.5.2 is vulnerable to privilege elevation due to incorrect handling of the PAC (Privilege Attribute Certificate) checksum. A remote, authenticated, attacker can cause the winbindd process to crash using a legitimate Kerberos ticket. A local service with access to the winbindd privileged pipe can cause winbindd to cache elevated access permissions.

    Published: 19 Dec 2016
    7.8
    High

    CVE-2016-10013

    Last Modified: 20 Apr 2025

    Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.

    Published: 19 Dec 2016
    8.8
    High

    CVE-2016-2123

    Last Modified: 21 Nov 2024

    A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any user who can write to the dnsRecord attribute over LDAP can trigger this memory corruption. By default, all authenticated LDAP users can write to the dnsRecord attribute on new DNS objects. This makes the defect a remote privilege escalation.

    Published: 19 Dec 2016
    7.5
    High

    CVE-2016-8739

    Last Modified: 20 Apr 2025

    The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apache Abdera Parser which expands XML entities by default which represents a major XXE risk.

    Published: 19 Dec 2016
    6.1
    Medium

    CVE-2016-6812

    Last Modified: 20 Apr 2025

    The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.

    Published: 19 Dec 2016
    4.3
    Medium

    CVE-2016-9592

    Last Modified: 21 Nov 2024

    openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each volume, this could lead to a denial of service attack as the number of API requests being sent to the cloud-provider exceeds the API's rate-limit.

    Published: 19 Dec 2016
    5.5
    Medium

    CVE-2016-10169

    Last Modified: 20 Apr 2025

    The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

    Published: 18 Dec 2016
    7.5
    High

    CVE-2016-9158

    Last Modified: 2 Jun 2026

    A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions). Specially crafted packets sent to port 80/tcp could cause the affected devices to go into defect mode. A cold restart is required to recover the system.

    Published: 17 Dec 2016
    8.1
    High

    CVE-2016-9160

    Last Modified: 12 Apr 2025

    A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.

    Published: 17 Dec 2016
    8
    High

    CVE-2016-7454

    Last Modified: 12 Apr 2025

    CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.

    Published: 17 Dec 2016
    7.8
    High

    CVE-2016-9949

    Last Modified: 12 Apr 2025

    An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.

    Published: 17 Dec 2016
    7.8
    High

    CVE-2016-9950

    Last Modified: 12 Apr 2025

    An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.

    Published: 17 Dec 2016
    6.5
    Medium

    CVE-2016-9951

    Last Modified: 12 Apr 2025

    An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on Apport crash files generated by local systems. The Relaunch button will be hidden when crash files are opened directly in Apport-GTK.

    Published: 17 Dec 2016
    6.1
    Medium

    CVE-2016-9997

    Last Modified: 12 Apr 2025

    SPIP 3.1.x suffers from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/puce_statut.php involving the `$id` parameter, as demonstrated by a /ecrire/?exec=puce_statut URL.

    Published: 17 Dec 2016
    6.1
    Medium

    CVE-2016-9998

    Last Modified: 12 Apr 2025

    SPIP 3.1.x suffer from a Reflected Cross Site Scripting Vulnerability in /ecrire/exec/info_plugin.php involving the `$plugin` parameter, as demonstrated by a /ecrire/?exec=info_plugin URL.

    Published: 17 Dec 2016
    5.9
    Medium

    CVE-2016-9159

    Last Modified: 2 Jun 2026

    A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V6 and below CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 PN/DP V7 CPU family (incl. SIPLUS variants) (All versions), SIMATIC S7-400 V6 and earlier CPU family (All versions), SIMATIC S7-400 V7 CPU family (All versions), SIMATIC S7-410 V8 CPU family (All versions), SIMATIC S7-410 V8 CPU family (incl. SIPLUS variants) (All versions). An attacker with network access to port 102/tcp (ISO-TSAP) or via Profibus could obtain credentials from the PLC if protection-level 2 is configured on the affected devices.

    Published: 17 Dec 2016
    9.1
    Critical

    CVE-2017-11147

    Last Modified: 20 Apr 2025

    In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c.

    Published: 17 Dec 2016
    7.8
    High

    CVE-2016-10168

    Last Modified: 20 Apr 2025

    Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.

    Published: 17 Dec 2016
    7.8
    High

    CVE-2016-8815

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8817

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer overflow, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8818

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a pointer passed from a user to the driver is used without validation, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8825

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8816

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8819

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a handle to a kernel object may be returned to the user, leading to possible denial of service or escalation of privileges.

    Published: 16 Dec 2016
    5.5
    Medium

    CVE-2016-8826

    Last Modified: 12 Apr 2025

    All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8814

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8813

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    6.1
    Medium

    CVE-2016-8820

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source of a strcpy() call, leading to denial of service or information disclosure.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8821

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where improper access controls may allow a user to access arbitrary physical memory, leading to an escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8822

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000E, 0x600000F, and 0x6000010 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8823

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where the size of an input buffer is not validated leading to a denial of service or possible escalation of privileges

    Published: 16 Dec 2016
    7.8
    High

    CVE-2016-8824

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, leading to escalation of privileges.

    Published: 16 Dec 2016
    6.5
    Medium

    CVE-2016-8827

    Last Modified: 12 Apr 2025

    NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.

    Published: 16 Dec 2016