CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2016-5225

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled form actions, which allowed a remote attacker to bypass Content Security Policy via a crafted HTML page.

    Published: 1 Dec 2016
    5.5
    Medium

    CVE-2016-9773

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9556.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2017-1000097

    Last Modified: 20 Apr 2025

    On Darwin, user's trust preferences for root certificates were not honored. If the user had a root certificate loaded in their Keychain that was explicitly not trusted, a Go program would still verify a connection using that root certificate.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2017-1000098

    Last Modified: 20 Apr 2025

    The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit. It was possible for an attacker to generate a multipart request crafted such that the server ran out of file descriptors.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5217

    Last Modified: 20 Apr 2025

    The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to privileged plugins, which allowed a remote attacker to bypass site isolation via a crafted HTML page.

    Published: 1 Dec 2016
    6.3
    Medium

    CVE-2016-5219

    Last Modified: 20 Apr 2025

    A heap use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-5226

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac executed javascript: URLs entered in the URL bar in the context of the current tab, which allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-5205

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 55.0.2883.75 for Linux, Windows and Mac, incorrectly handles deferred page loads, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-5207

    Last Modified: 20 Apr 2025

    In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-5208

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 55.0.2883.75 for Linux and Windows, and 55.0.2883.84 for Android allowed possible corruption of the DOM tree during synchronous event handling, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5209

    Last Modified: 20 Apr 2025

    Bad casting in bitmap manipulation in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5210

    Last Modified: 20 Apr 2025

    Heap buffer overflow during TIFF image parsing in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5213

    Last Modified: 20 Apr 2025

    A use after free in V8 in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 1 Dec 2016
    4.3
    Medium

    CVE-2016-5214

    Last Modified: 20 Apr 2025

    Google Chrome prior to 55.0.2883.75 for Windows mishandled downloaded files, which allowed a remote attacker to prevent the downloaded file from receiving the Mark of the Web via a crafted HTML page.

    Published: 1 Dec 2016
    6.3
    Medium

    CVE-2016-5215

    Last Modified: 20 Apr 2025

    A use after free in webaudio in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 1 Dec 2016
    6.3
    Medium

    CVE-2016-5216

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5220

    Last Modified: 20 Apr 2025

    PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to read local files via a crafted PDF file.

    Published: 1 Dec 2016
    6.3
    Medium

    CVE-2016-5221

    Last Modified: 20 Apr 2025

    Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed a remote attacker to bypass buffer validation via a crafted HTML page.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5222

    Last Modified: 20 Apr 2025

    Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5223

    Last Modified: 20 Apr 2025

    Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption or DoS via a crafted PDF file.

    Published: 1 Dec 2016
    4.3
    Medium

    CVE-2016-5224

    Last Modified: 20 Apr 2025

    A timing attack on denormalized floating point arithmetic in SVG filters in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.

    Published: 1 Dec 2016
    9.8
    Critical

    CVE-2016-9652

    Last Modified: 21 Nov 2024

    Multiple unspecified vulnerabilities in Google Chrome before 55.0.2883.75.

    Published: 1 Dec 2016
    5.5
    Medium

    CVE-2016-9685

    Last Modified: 12 Apr 2025

    Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.

    Published: 1 Dec 2016
    7.8
    High

    CVE-2017-0386

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2017-7223

    Last Modified: 20 Apr 2025

    GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.

    Published: 1 Dec 2016
    5.5
    Medium

    CVE-2017-7224

    Last Modified: 20 Apr 2025

    The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2017-7225

    Last Modified: 20 Apr 2025

    The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash.

    Published: 1 Dec 2016
    7.5
    High

    CVE-2016-9079

    Last Modified: 4 Nov 2025

    A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

    Published: 1 Dec 2016
    6.5
    Medium

    CVE-2016-5212

    Last Modified: 20 Apr 2025

    Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a remote attacker to read local files via a crafted HTML page.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5203

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 1 Dec 2016
    6.1
    Medium

    CVE-2016-5204

    Last Modified: 20 Apr 2025

    Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-5211

    Last Modified: 20 Apr 2025

    A use after free in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 1 Dec 2016
    4.3
    Medium

    CVE-2016-9650

    Last Modified: 20 Apr 2025

    Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled iframes, which allowed a remote attacker to bypass a no-referrer policy via a crafted HTML page.

    Published: 1 Dec 2016
    8.8
    High

    CVE-2016-9651

    Last Modified: 21 Nov 2024

    A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Published: 1 Dec 2016
    5.4
    Medium

    CVE-2017-2633

    Last Modified: 21 Nov 2024

    An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.

    Published: 1 Dec 2016
    8
    High

    CVE-2016-2884

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3.1, in an unspecified non-default configuration, allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 30 Nov 2016
    8.1
    High

    CVE-2016-2887

    Last Modified: 12 Apr 2025

    IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 30 Nov 2016
    6.5
    Medium

    CVE-2016-2881

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 and QRadar Incident Forensics 7.2 before 7.2.7 allow remote attackers to bypass intended access restrictions via modified request parameters.

    Published: 30 Nov 2016
    8.8
    High

    CVE-2016-2917

    Last Modified: 12 Apr 2025

    The notifications component in IBM TRIRIGA Applications 10.4 and 10.5 before 10.5.1 allows remote authenticated users to obtain sensitive password information, and consequently gain privileges, via unspecified vectors.

    Published: 30 Nov 2016
    3.1
    Low

    CVE-2016-2874

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 30 Nov 2016
    7.5
    High

    CVE-2016-2876

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 executes unspecified processes at an incorrect privilege level, which makes it easier for remote authenticated users to obtain root access by leveraging a command-injection issue.

    Published: 30 Nov 2016
    3.3
    Low

    CVE-2016-2877

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.

    Published: 30 Nov 2016
    8.8
    High

    CVE-2016-2873

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 30 Nov 2016
    7.8
    High

    CVE-2016-2871

    Last Modified: 12 Apr 2025

    IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information by reading a configuration file.

    Published: 30 Nov 2016
    5.4
    Medium

    CVE-2016-2869

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the UI in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote authenticated users to inject arbitrary web script or HTML via crafted fields in a URL.

    Published: 30 Nov 2016
    8
    High

    CVE-2016-2878

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 allow remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 30 Nov 2016
    4.4
    Medium

    CVE-2016-8222

    Last Modified: 12 Apr 2025

    A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.

    Published: 30 Nov 2016
    6.1
    Medium

    CVE-2016-2934

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Nov 2016
    7.3
    High

    CVE-2016-2936

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 uses cleartext storage for unspecified passwords, which allows local users to obtain sensitive information via unknown vectors.

    Published: 30 Nov 2016
    3.7
    Low

    CVE-2016-2951

    Last Modified: 12 Apr 2025

    IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffing the network and performing calculations on encrypted data.

    Published: 30 Nov 2016