CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2016-9385

    Last Modified: 20 Apr 2025

    The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of service (host crash) by leveraging lack of canonical address checks.

    Published: 22 Nov 2016
    7.8
    High

    CVE-2016-9386

    Last Modified: 20 Apr 2025

    The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.

    Published: 22 Nov 2016
    5.5
    Medium

    CVE-2016-9807

    Last Modified: 20 Apr 2025

    The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted FLIC file.

    Published: 22 Nov 2016
    5.5
    Medium

    CVE-2016-9756

    Last Modified: 12 Apr 2025

    arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.

    Published: 22 Nov 2016
    9.8
    Critical

    CVE-2014-9911

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.1 for C/C++ allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted uloc_getDisplayName call.

    Published: 22 Nov 2016
    5.5
    Medium

    CVE-2016-9377

    Last Modified: 20 Apr 2025

    Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging IDT entry miscalculation.

    Published: 22 Nov 2016
    7.9
    High

    CVE-2016-9379

    Last Modified: 20 Apr 2025

    The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via string quotes and S-expressions in the bootloader configuration file.

    Published: 22 Nov 2016
    7.5
    High

    CVE-2016-9381

    Last Modified: 20 Apr 2025

    Race condition in QEMU in Xen allows local x86 HVM guest OS administrators to gain privileges by changing certain data on shared rings, aka a "double fetch" vulnerability.

    Published: 22 Nov 2016
    6.5
    Medium

    CVE-2016-9384

    Last Modified: 20 Apr 2025

    Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.

    Published: 22 Nov 2016
    7.5
    High

    CVE-2016-6817

    Last Modified: 20 Apr 2025

    The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.

    Published: 22 Nov 2016
    6.7
    Medium

    CVE-2016-8641

    Last Modified: 21 Nov 2024

    A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

    Published: 22 Nov 2016
    5.5
    Medium

    CVE-2016-9378

    Last Modified: 20 Apr 2025

    Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.

    Published: 22 Nov 2016
    7.5
    High

    CVE-2016-9380

    Last Modified: 20 Apr 2025

    The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or delete arbitrary files on the host via NUL bytes in the bootloader configuration file.

    Published: 22 Nov 2016
    7.8
    High

    CVE-2016-9382

    Last Modified: 20 Apr 2025

    Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a denial of service (guest OS crash) by leveraging a guest operating system that uses hardware task switching and allows a new task to start in VM86 mode.

    Published: 22 Nov 2016
    7.1
    High

    CVE-2016-6816

    Last Modified: 20 Apr 2025

    The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

    Published: 22 Nov 2016
    7.5
    High

    CVE-2016-7426

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.

    Published: 21 Nov 2016
    3.7
    Low

    CVE-2016-7429

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p9 changes the peer structure to the interface it receives the response from a source, which allows remote attackers to cause a denial of service (prevent communication with a source) by sending a response for a source to an interface the source does not use.

    Published: 21 Nov 2016
    7.5
    High

    CVE-2016-7434

    Last Modified: 20 Apr 2025

    The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

    Published: 21 Nov 2016
    6.5
    Medium

    CVE-2016-9310

    Last Modified: 20 Apr 2025

    The control mode (mode 6) functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to set or unset traps via a crafted control mode packet.

    Published: 21 Nov 2016
    6.5
    Medium

    CVE-2016-9914

    Last Modified: 12 Apr 2025

    Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.

    Published: 21 Nov 2016
    6.5
    Medium

    CVE-2016-9916

    Last Modified: 12 Apr 2025

    Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend.

    Published: 21 Nov 2016
    4.3
    Medium

    CVE-2016-7427

    Last Modified: 20 Apr 2025

    The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode packet.

    Published: 21 Nov 2016
    5.3
    Medium

    CVE-2016-7431

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerability exists because of a CVE-2015-8138 regression.

    Published: 21 Nov 2016
    4.3
    Medium

    CVE-2016-7428

    Last Modified: 20 Apr 2025

    ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet.

    Published: 21 Nov 2016
    5.3
    Medium

    CVE-2016-7433

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified impact via unknown vectors, related to a "root distance that did not include the peer dispersion."

    Published: 21 Nov 2016
    9.1
    Critical

    CVE-2016-8638

    Last Modified: 20 Apr 2025

    A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that allows attacker to log out active sessions of other users. This issue is related to how it tracks sessions, and allows an unauthenticated attacker to view and terminate active sessions from other users. It is also called a "SAML2 multi-session vulnerability."

    Published: 21 Nov 2016
    5.9
    Medium

    CVE-2016-9311

    Last Modified: 20 Apr 2025

    ntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted packet.

    Published: 21 Nov 2016
    7.5
    High

    CVE-2016-9312

    Last Modified: 20 Apr 2025

    ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

    Published: 21 Nov 2016
    9.8
    Critical

    CVE-2016-9635

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer.

    Published: 21 Nov 2016
    9.8
    Critical

    CVE-2016-9636

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer.

    Published: 21 Nov 2016
    6.5
    Medium

    CVE-2016-9913

    Last Modified: 12 Apr 2025

    Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the order of resource cleanup.

    Published: 21 Nov 2016
    9.8
    Critical

    CVE-2016-9634

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter.

    Published: 21 Nov 2016
    7.5
    High

    CVE-2016-9808

    Last Modified: 20 Apr 2025

    The FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted series of skip and count pairs.

    Published: 21 Nov 2016
    6.5
    Medium

    CVE-2016-9915

    Last Modified: 12 Apr 2025

    Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle backend.

    Published: 21 Nov 2016
    7.8
    High

    CVE-2016-9560

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified impact via a crafted image.

    Published: 20 Nov 2016
    7.8
    High

    CVE-2016-1248

    Last Modified: 12 Apr 2025

    vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.

    Published: 20 Nov 2016
    5.5
    Medium

    CVE-2017-5503

    Last Modified: 20 Apr 2025

    The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image.

    Published: 20 Nov 2016
    5.5
    Medium

    CVE-2017-5504

    Last Modified: 20 Apr 2025

    The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.

    Published: 20 Nov 2016
    5.5
    Medium

    CVE-2017-5505

    Last Modified: 20 Apr 2025

    The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.

    Published: 20 Nov 2016
    9.8
    Critical

    CVE-2016-9150

    Last Modified: 12 Apr 2025

    Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 19 Nov 2016
    7.8
    High

    CVE-2016-9151

    Last Modified: 12 Apr 2025

    Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.

    Published: 19 Nov 2016
    6.5
    Medium

    CVE-2016-9149

    Last Modified: 12 Apr 2025

    The Addresses Object parser in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 mishandles single quote characters, which allows remote authenticated users to conduct XPath injection attacks via a crafted string.

    Published: 19 Nov 2016
    7.5
    High

    CVE-2016-6460

    Last Modified: 12 Apr 2025

    A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass FTP malware detection rules and download malware over an FTP connection. Cisco Firepower System Software is affected when the device has a file policy with malware block configured for FTP connections. More Information: CSCuv36188 CSCuy91156. Known Affected Releases: 5.4.0.2 5.4.1.1 5.4.1.6 6.0.0 6.1.0 6.2.0. Known Fixed Releases: 6.0.0.

    Published: 19 Nov 2016
    2.5
    Low

    CVE-2016-6450

    Last Modified: 12 Apr 2025

    A vulnerability in the package unbundle utility of Cisco IOS XE Software could allow an authenticated, local attacker to gain write access to some files in the underlying operating system. This vulnerability affects the following products if they are running a vulnerable release of Cisco IOS XE Software: Cisco 5700 Series Wireless LAN Controllers, Cisco Catalyst 3650 Series Switches, Cisco Catalyst 3850 Series Switches, Cisco Catalyst 4500E Series Switches, Cisco Catalyst 4500X Series Switches. More Information: CSCva60013 CSCvb22622. Known Affected Releases: 3.7(0) 16.4.1 Denali-16.1.3 Denali-16.2.2 Denali-16.3.1. Known Fixed Releases: 15.2(4)E3 16.1(2.208) 16.2(2.42) 16.3(1.22) 16.4(0.190) 16.5(0.29).

    Published: 19 Nov 2016
    5.5
    Medium

    CVE-2016-6459

    Last Modified: 12 Apr 2025

    Cisco TelePresence endpoints running either CE or TC software contain a vulnerability that could allow an authenticated, local attacker to execute a local shell command injection. More Information: CSCvb25010. Known Affected Releases: 8.1.x. Known Fixed Releases: 6.3.4 7.3.7 8.2.2 8.3.0.

    Published: 19 Nov 2016
    5.3
    Medium

    CVE-2016-6463

    Last Modified: 12 Apr 2025

    A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for both virtual and hardware versions of Cisco Email Security Appliances, if the AMP feature is configured to scan incoming email attachments. More Information: CSCuz85823. Known Affected Releases: 10.0.0-082 9.7.0-125 9.7.1-066. Known Fixed Releases: 10.0.0-203 9.7.2-131.

    Published: 19 Nov 2016
    6.5
    Medium

    CVE-2016-6457

    Last Modified: 12 Apr 2025

    A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects Cisco Nexus 9000 Series Leaf Switches (TOR) - ACI Mode and Cisco Application Policy Infrastructure Controller (APIC). More Information: CSCuy93241. Known Affected Releases: 11.2(2x) 11.2(3x) 11.3(1x) 11.3(2x) 12.0(1x). Known Fixed Releases: 11.2(2i) 11.2(2j) 11.2(3f) 11.2(3g) 11.2(3h) 11.2(3l) 11.3(0.236) 11.3(1j) 11.3(2i) 11.3(2j) 12.0(1r).

    Published: 19 Nov 2016
    7.5
    High

    CVE-2016-6458

    Last Modified: 12 Apr 2025

    A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass content filters configured on an affected device. Email that should have been filtered could instead be forwarded by the device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for Cisco Email Security Appliances, both virtual and hardware appliances, if the software is configured to use a content filter for email attachments that are protected or encrypted. More Information: CSCva52546. Known Affected Releases: 10.0.0-125 9.7.1-066.

    Published: 19 Nov 2016
    5.9
    Medium

    CVE-2016-6461

    Last Modified: 12 Apr 2025

    A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to inject arbitrary XML commands on the affected system. More Information: CSCva38556. Known Affected Releases: 9.1(6.10). Known Fixed Releases: 100.11(0.75) 100.15(0.137) 100.8(40.129) 96.2(0.95) 97.1(0.55) 97.1(12.7) 97.1(6.30).

    Published: 19 Nov 2016
    5.3
    Medium

    CVE-2016-6462

    Last Modified: 12 Apr 2025

    A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. This vulnerability affects all releases prior to the first fixed release of Cisco AsyncOS Software for both virtual and hardware versions of Cisco Email Security Appliances, if the AMP feature is configured to scan incoming email attachments. More Information: CSCva13456. Known Affected Releases: 10.0.0-082 10.0.0-125 9.7.1-066. Known Fixed Releases: 10.0.0-203 9.7.2-131.

    Published: 19 Nov 2016