CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-9861

    Last Modified: 12 Apr 2025

    An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.

    Published: 11 Dec 2016
    7.5
    High

    CVE-2016-9862

    Last Modified: 12 Apr 2025

    An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.

    Published: 11 Dec 2016
    7.5
    High

    CVE-2016-9863

    Last Modified: 12 Apr 2025

    An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) attack. All 4.6.x versions (prior to 4.6.5) are affected.

    Published: 11 Dec 2016
    5.5
    Medium

    CVE-2016-10028

    Last Modified: 20 Apr 2025

    The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a VIRTIO_GPU_CMD_GET_CAPSET command with a maximum capabilities size with a value of 0.

    Published: 11 Dec 2016
    7.5
    High

    CVE-2016-10146

    Last Modified: 20 Apr 2025

    Multiple memory leaks in the caption and label handling code in ImageMagick allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 11 Dec 2016
    9.8
    Critical

    CVE-2016-6496

    Last Modified: 12 Apr 2025

    The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.

    Published: 9 Dec 2016
    9.8
    Critical

    CVE-2016-6501

    Last Modified: 12 Apr 2025

    JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.

    Published: 9 Dec 2016
    6.1
    Medium

    CVE-2016-6523

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2) link_type parameter to admin/media.php.

    Published: 9 Dec 2016
    9.8
    Critical

    CVE-2016-6829

    Last Modified: 12 Apr 2025

    The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 9 Dec 2016
    9.9
    Critical

    CVE-2016-9832

    Last Modified: 12 Apr 2025

    PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2) Internet Communication Framework (ICF) over HTTP or HTTPS, as demonstrated by WEBGUI or Report.

    Published: 9 Dec 2016
    6.1
    Medium

    CVE-2016-6810

    Last Modified: 21 Nov 2024

    In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.

    Published: 9 Dec 2016
    5.5
    Medium

    CVE-2016-9583

    Last Modified: 21 Nov 2024

    An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.

    Published: 9 Dec 2016
    7.8
    High

    CVE-2016-9120

    Last Modified: 12 Apr 2025

    Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (use-after-free) by calling ION_IOC_FREE on two CPUs at the same time.

    Published: 8 Dec 2016
    7.5
    High

    CVE-2016-9920

    Last Modified: 12 Apr 2025

    steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

    Published: 8 Dec 2016
    6.7
    Medium

    CVE-2016-8103

    Last Modified: 12 Apr 2025

    SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

    Published: 8 Dec 2016
    5.5
    Medium

    CVE-2016-8104

    Last Modified: 12 Apr 2025

    Buffer overflow in Intel PROSet/Wireless Software and Drivers in versions before 19.20.3 allows a local user to crash iframewrk.exe causing a potential denial of service.

    Published: 8 Dec 2016
    7.8
    High

    CVE-2016-8102

    Last Modified: 12 Apr 2025

    Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges.

    Published: 8 Dec 2016
    7.5
    High

    CVE-2016-9839

    Last Modified: 12 Apr 2025

    In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.

    Published: 8 Dec 2016
    7.5
    High

    CVE-2016-9919

    Last Modified: 12 Apr 2025

    The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote attackers to cause a denial of service (panic) via a fragmented IPv6 packet.

    Published: 8 Dec 2016
    7.5
    High

    CVE-2016-9933

    Last Modified: 12 Apr 2025

    Stack consumption vulnerability in the gdImageFillToBorder function in gd.c in the GD Graphics Library (aka libgd) before 2.2.2, as used in PHP before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service (segmentation violation) via a crafted imagefilltoborder call that triggers use of a negative color value.

    Published: 8 Dec 2016
    9.8
    Critical

    CVE-2016-9935

    Last Modified: 12 Apr 2025

    The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) or possibly have unspecified other impact via an empty boolean element in a wddxPacket XML document.

    Published: 8 Dec 2016
    9.8
    Critical

    CVE-2016-9936

    Last Modified: 12 Apr 2025

    The unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted serialized data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6834.

    Published: 8 Dec 2016
    7.8
    High

    CVE-2015-8967

    Last Modified: 12 Apr 2025

    arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.

    Published: 8 Dec 2016
    9.8
    Critical

    CVE-2017-3159

    Last Modified: 20 Apr 2025

    Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization vulnerability. De-serializing untrusted data can lead to security flaws.

    Published: 8 Dec 2016
    6.5
    Medium

    CVE-2016-9579

    Last Modified: 21 Nov 2024

    A flaw was found in the way Ceph Object Gateway would process cross-origin HTTP requests if the CORS policy was set to allow origin on a bucket. A remote unauthenticated attacker could use this flaw to cause denial of service by sending a specially-crafted cross-origin HTTP request. Ceph branches 1.3.x and 2.x are affected.

    Published: 8 Dec 2016
    5.5
    Medium

    CVE-2016-9888

    Last Modified: 12 Apr 2025

    An error within the "tar_directory_for_file()" function (gsf-infile-tar.c) in GNOME Structured File Library before 1.14.41 can be exploited to trigger a Null pointer dereference and subsequently cause a crash via a crafted TAR file.

    Published: 7 Dec 2016
    3.1
    Low

    CVE-2016-8651

    Last Modified: 21 Nov 2024

    An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.

    Published: 7 Dec 2016
    9.8
    Critical

    CVE-2016-8749

    Last Modified: 20 Apr 2025

    Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.

    Published: 7 Dec 2016
    3.3
    Low

    CVE-2016-9580

    Last Modified: 21 Nov 2024

    An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.

    Published: 7 Dec 2016
    3.3
    Low

    CVE-2016-9581

    Last Modified: 21 Nov 2024

    An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.

    Published: 7 Dec 2016
    7.8
    High

    CVE-2016-9566

    Last Modified: 12 Apr 2025

    base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

    Published: 7 Dec 2016
    Unknown

    CVE-2014-9299

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8870. Reason: This candidate is a duplicate of CVE-2015-8870. The CVE-2014-9299 ID originated from an unrelated and invalid assignment, and this ID was inadvertently used for the CVE-2015-8870 issue. Notes: All CVE users should reference CVE-2015-8870 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Dec 2016
    Unknown

    CVE-2016-8601

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue in a "generally available" software product. Notes: none

    Published: 6 Dec 2016
    Unknown

    CVE-2016-9300

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Dec 2016
    Unknown

    CVE-2016-9301

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Dec 2016
    Unknown

    CVE-2016-9302

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 6 Dec 2016
    5.9
    Medium

    CVE-2016-5341

    Last Modified: 12 Apr 2025

    The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 31470303 and external bug 211602 (and AndroidID-7225554).

    Published: 6 Dec 2016
    7.5
    High

    CVE-2017-1000189

    Last Modified: 20 Apr 2025

    nodejs ejs version older than 2.5.5 is vulnerable to a denial-of-service due to weak input validation in the ejs.renderFile()

    Published: 6 Dec 2016
    7.5
    High

    CVE-2016-9637

    Last Modified: 20 Apr 2025

    The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS administrators to gain qemu process privileges via vectors involving an out-of-range ioport access.

    Published: 6 Dec 2016
    7.8
    High

    CVE-2016-8655

    Last Modified: 12 Apr 2025

    Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

    Published: 6 Dec 2016
    6.1
    Medium

    CVE-2017-1000188

    Last Modified: 20 Apr 2025

    nodejs ejs version older than 2.5.5 is vulnerable to a Cross-site-scripting in the ejs.renderFile() resulting in code injection

    Published: 6 Dec 2016
    5.5
    Medium

    CVE-2016-10349

    Last Modified: 20 Apr 2025

    The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 6 Dec 2016
    5.5
    Medium

    CVE-2016-10350

    Last Modified: 20 Apr 2025

    The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

    Published: 6 Dec 2016
    7.5
    High

    CVE-2016-3104

    Last Modified: 20 Apr 2025

    mongod in MongoDB 2.6, when using 2.4-style users, and 2.4 allow remote attackers to cause a denial of service (memory consumption and process termination) by leveraging in-memory database representation when authenticating against a non-existent database.

    Published: 6 Dec 2016
    7.5
    High

    CVE-2017-7304

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.

    Published: 6 Dec 2016
    6.1
    Medium

    CVE-2016-9152

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in ecrire/exec/plonger.php in SPIP 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the rac parameter.

    Published: 5 Dec 2016
    5.6
    Medium

    CVE-2016-7171

    Last Modified: 12 Apr 2025

    NetApp Plug-in for Symantec NetBackup prior to version 2.0.1 makes use of a non-unique server certificate, making it vulnerable to impersonation.

    Published: 5 Dec 2016
    9.8
    Critical

    CVE-2016-9836

    Last Modified: 12 Apr 2025

    The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.

    Published: 5 Dec 2016
    9.8
    Critical

    CVE-2016-9157

    Last Modified: 12 Apr 2025

    A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.

    Published: 5 Dec 2016
    7.3
    High

    CVE-2016-9156

    Last Modified: 12 Apr 2025

    A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.

    Published: 5 Dec 2016