CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-9835

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.

    Published: 5 Dec 2016
    4
    Medium

    CVE-2016-9844

    Last Modified: 20 Apr 2025

    Buffer overflow in the zi_short function in zipinfo.c in Info-Zip UnZip 6.0 allows remote attackers to cause a denial of service (crash) via a large compression method value in the central directory file header.

    Published: 5 Dec 2016
    7
    High

    CVE-2016-8399

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and current compiler optimizations restrict access to the vulnerable code. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31349935.

    Published: 5 Dec 2016
    5.5
    Medium

    CVE-2016-10095

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7 and 4.0.8 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.

    Published: 4 Dec 2016
    7.5
    High

    CVE-2016-8740

    Last Modified: 12 Apr 2025

    The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.

    Published: 4 Dec 2016
    9.8
    Critical

    CVE-2016-9796

    Last Modified: 12 Apr 2025

    Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the privilege of NT AUTHORITY\SYSTEM on the server. NOTE: The discoverer states "The vendor position is to refer to the technical guidelines of the product security deployment to mitigate this issue, which means applying proper firewall rules to prevent unauthorised clients to connect to the OmniVista server."

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-10269

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 512" and libtiff/tif_unix.c:340:2.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9799

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-8707

    Last Modified: 12 Apr 2025

    An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.

    Published: 3 Dec 2016
    7.5
    High

    CVE-2017-7301

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability could lead to a GNU linker (ld) program crash.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-10270

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 8" and libtiff/tif_read.c:523:22.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-10092

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the readContigStripsIntoBuffer function in tif_unix.c in LibTIFF 4.0.7, 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5 and 4.0.6 allows remote attackers to have unspecified impact via a crafted image.

    Published: 3 Dec 2016
    5.5
    Medium

    CVE-2016-10267

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_ojpeg.c:816:8.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-10271

    Last Modified: 20 Apr 2025

    tools/tiffcrop.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer over-read and buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 1" and libtiff/tif_fax3.c:413:13.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-10272

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.7 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted TIFF image, related to "WRITE of size 2048" and libtiff/tif_next.c:64:9.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9797

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9802

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9804

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "frm->ptr" parameter. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9801

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9803

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed.

    Published: 3 Dec 2016
    7.5
    High

    CVE-2017-7302

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.

    Published: 3 Dec 2016
    7.5
    High

    CVE-2017-7303

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerability causes Binutils utilities like strip to crash.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9798

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

    Published: 3 Dec 2016
    5.3
    Medium

    CVE-2016-9800

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists because "pin" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "pin_code_reply_cp *cp" parameter.

    Published: 3 Dec 2016
    7.8
    High

    CVE-2016-9638

    Last Modified: 12 Apr 2025

    In BMC Patrol before 9.13.10.02, the binary "listguests64" is configured with the setuid bit. However, when executing it, it will look for a binary named "virsh" using the PATH environment variable. The "listguests64" program will then run "virsh" using root privileges. This allows local users to elevate their privileges to root.

    Published: 2 Dec 2016
    7.5
    High

    CVE-2016-9479

    Last Modified: 12 Apr 2025

    The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

    Published: 2 Dec 2016
    7.8
    High

    CVE-2016-10153

    Last Modified: 20 Apr 2025

    The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by leveraging reliance on earlier net/ceph/crypto.c code.

    Published: 2 Dec 2016
    7.8
    High

    CVE-2016-9793

    Last Modified: 12 Apr 2025

    The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.

    Published: 2 Dec 2016
    5.5
    Medium

    CVE-2016-10266

    Last Modified: 20 Apr 2025

    LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted TIFF image, related to libtiff/tif_read.c:351:22.

    Published: 2 Dec 2016
    7.8
    High

    CVE-2016-10268

    Last Modified: 20 Apr 2025

    tools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (integer underflow and heap-based buffer under-read) or possibly have unspecified other impact via a crafted TIFF image, related to "READ of size 78490" and libtiff/tif_unix.c:115:23.

    Published: 2 Dec 2016
    7.5
    High

    CVE-2016-10396

    Last Modified: 20 Apr 2025

    The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote endpoint by repeatedly sending ISAKMP fragment packets in a particular order such that the worst-case computational complexity is realized in the algorithm utilized to determine if reassembly of the fragments can take place.

    Published: 2 Dec 2016
    7.5
    High

    CVE-2017-7300

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.

    Published: 2 Dec 2016
    5.5
    Medium

    CVE-2016-10147

    Last Modified: 20 Apr 2025

    crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5).

    Published: 2 Dec 2016
    7.5
    High

    CVE-2017-7227

    Last Modified: 20 Apr 2025

    GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.

    Published: 2 Dec 2016
    5.5
    Medium

    CVE-2017-7299

    Last Modified: 20 Apr 2025

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.

    Published: 2 Dec 2016
    5.4
    Medium

    CVE-2016-2991

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Protector for Mail Security 2.8.0.0 through 2.8.1.0 before 2.8.1.0-22115 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Dec 2016
    8.1
    High

    CVE-2016-3055

    Last Modified: 12 Apr 2025

    IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-9751

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 1 Dec 2016
    8.6
    High

    CVE-2016-9752

    Last Modified: 12 Apr 2025

    In Serendipity before 2.0.5, an attacker can bypass SSRF protection by using a malformed IP address (e.g., http://127.1) or a 30x (aka Redirection) HTTP status code.

    Published: 1 Dec 2016
    6.8
    Medium

    CVE-2016-3047

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM FileNet Workplace 4.0.2 through 4.0.2.14 IF001 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 1 Dec 2016
    7.8
    High

    CVE-2016-2946

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.

    Published: 1 Dec 2016
    5.4
    Medium

    CVE-2016-2955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Connections 5.0 before CR4 and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Dec 2016
    5.4
    Medium

    CVE-2016-2994

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM UrbanCode Deploy 6.2.x before 6.2.1.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2016-3012

    Last Modified: 12 Apr 2025

    IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials.

    Published: 1 Dec 2016
    8.1
    High

    CVE-2016-3033

    Last Modified: 12 Apr 2025

    IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2016-10199

    Last Modified: 17 Mar 2026

    The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted tag value.

    Published: 1 Dec 2016
    5.5
    Medium

    CVE-2016-10198

    Last Modified: 17 Mar 2026

    The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted audio file.

    Published: 1 Dec 2016
    9.1
    Critical

    CVE-2017-7226

    Last Modified: 20 Apr 2025

    The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure as well.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5206

    Last Modified: 20 Apr 2025

    The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5218

    Last Modified: 20 Apr 2025

    The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to temporarily spoof the contents of the Omnibox (URL bar) via a crafted HTML page containing PDF data.

    Published: 1 Dec 2016