CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-6466

    Last Modified: 12 Apr 2025

    A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remote attacker to terminate all active IPsec VPN tunnels and prevent new tunnels from establishing, resulting in a denial of service (DoS) condition. This vulnerability affects the following Cisco products: Cisco ASR 5000/5500 Series routers, Cisco Virtualized Packet Core (VPC). More Information: CSCva13631. Known Affected Releases: 20.0.0 20.1.0 20.2.0 20.2.3 20.2.v1 21.0.0 21.0.M0.64246. Known Fixed Releases: 20.2.3 20.2.3.65026 20.2.a4.65307 20.2.v1 20.2.v1.65353 20.3.M0.65037 20.3.T0.65043 21.0.0 21.0.0.65256 21.0.M0.64595 21.0.M0.64860 21.0.M0.65140 21.0.V0.65052 21.0.V0.65150 21.0.V0.65366 21.0.VC0.64639 21.1.A0.64861 21.1.A0.65145 21.1.PP0.65270 21.1.R0.65130 21.1.R0.65135 21.1.R0.65154 21.1.VC0.64898 21.1.VC0.65203 21.2.A0.65147.

    Published: 19 Nov 2016
    6.1
    Medium

    CVE-2016-6472

    Last Modified: 12 Apr 2025

    A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system. More Information: CSCvb37121. Known Affected Releases: 11.5(1.2). Known Fixed Releases: 11.5(1.11950.96) 11.5(1.12900.2) 12.0(0.98000.133) 12.0(0.98000.313) 12.0(0.98000.404).

    Published: 19 Nov 2016
    5.5
    Medium

    CVE-2016-9556

    Last Modified: 20 Apr 2025

    The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.

    Published: 19 Nov 2016
    6.5
    Medium

    CVE-2016-9559

    Last Modified: 20 Apr 2025

    coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image.

    Published: 19 Nov 2016
    9.8
    Critical

    CVE-2016-9558

    Last Modified: 20 Apr 2025

    (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negation overflow."

    Published: 19 Nov 2016
    7.5
    High

    CVE-2016-8562

    Last Modified: 21 Apr 2026

    A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables could reduce the availability or cause a denial-of-service.

    Published: 18 Nov 2016
    6.6
    Medium

    CVE-2016-8561

    Last Modified: 12 Apr 2025

    A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Users with elevated privileges to TIA-Portal and project data on the engineering station could possibly get privileged access on affected devices.

    Published: 18 Nov 2016
    6.5
    Medium

    CVE-2016-9632

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

    Published: 18 Nov 2016
    7
    High

    CVE-2016-10200

    Last Modified: 20 Apr 2025

    Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.

    Published: 18 Nov 2016
    8.1
    High

    CVE-2016-1251

    Last Modified: 12 Apr 2025

    There is a vulnerability of type use-after-free affecting DBD::mysql (aka DBD-mysql or the Database Interface (DBI) MySQL driver for Perl) 3.x and 4.x before 4.041 when used with mysql_server_prepare=1.

    Published: 18 Nov 2016
    6
    Medium

    CVE-2017-12168

    Last Modified: 20 Apr 2025

    The access_pmu_evcntr function in arch/arm64/kvm/sys_regs.c in the Linux kernel before 4.8.11 allows privileged KVM guest OS users to cause a denial of service (assertion failure and host OS crash) by accessing the Performance Monitors Cycle Count Register (PMCCNTR).

    Published: 18 Nov 2016
    7.8
    High

    CVE-2016-9453

    Last Modified: 20 Apr 2025

    The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.

    Published: 18 Nov 2016
    9.8
    Critical

    CVE-2016-10714

    Last Modified: 21 Nov 2024

    In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.

    Published: 17 Nov 2016
    5.5
    Medium

    CVE-2016-9401

    Last Modified: 6 Aug 2025

    popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.

    Published: 17 Nov 2016
    6.5
    Medium

    CVE-2016-9630

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

    Published: 17 Nov 2016
    6.5
    Medium

    CVE-2016-9631

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 17 Nov 2016
    7.5
    High

    CVE-2016-9066

    Last Modified: 25 Nov 2025

    A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9064

    Last Modified: 25 Nov 2025

    Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

    Published: 16 Nov 2016
    9.8
    Critical

    CVE-2016-5297

    Last Modified: 25 Nov 2025

    An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 16 Nov 2016
    5.5
    Medium

    CVE-2016-5291

    Last Modified: 25 Nov 2025

    A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 16 Nov 2016
    9.8
    Critical

    CVE-2016-5290

    Last Modified: 25 Nov 2025

    Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9372

    Last Modified: 12 Apr 2025

    In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in plugins/profinet/packet-pn-rtc-one.c by rejecting input with too many I/O objects.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-5296

    Last Modified: 25 Nov 2025

    A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9376

    Last Modified: 12 Apr 2025

    In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-openflow_v5.c by ensuring that certain length values were sufficiently large.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-9399

    Last Modified: 20 Apr 2025

    The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

    Published: 16 Nov 2016
    9.1
    Critical

    CVE-2016-9480

    Last Modified: 12 Apr 2025

    libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9374

    Last Modified: 12 Apr 2025

    In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-alljoyn.c by ensuring that a length variable properly tracked the state of a signature variable.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-9397

    Last Modified: 20 Apr 2025

    The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

    Published: 16 Nov 2016
    5.3
    Medium

    CVE-2016-8635

    Last Modified: 21 Nov 2024

    It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9375

    Last Modified: 12 Apr 2025

    In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dtn.c by checking whether SDNV evaluation was successful.

    Published: 16 Nov 2016
    5.9
    Medium

    CVE-2016-9373

    Last Modified: 12 Apr 2025

    In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DCERPC dissector could crash with a use-after-free, triggered by network traffic or a capture file. This was addressed in epan/dissectors/packet-dcerpc-nt.c and epan/dissectors/packet-dcerpc-spoolss.c by using the wmem file scope for private strings.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-9396

    Last Modified: 20 Apr 2025

    The JPC_NOMINALGAIN function in jpc/jpc_t1cod.c in JasPer through 2.0.12 allows remote attackers to cause a denial of service (JPC_COX_RFT assertion failure) via unspecified vectors.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-9398

    Last Modified: 20 Apr 2025

    The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-9448

    Last Modified: 20 Apr 2025

    The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297.

    Published: 16 Nov 2016
    7.5
    High

    CVE-2016-5285

    Last Modified: 21 Nov 2024

    A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

    Published: 16 Nov 2016
    9.1
    Critical

    CVE-2016-5763

    Last Modified: 12 Apr 2025

    Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform unauthorized file access and modification.

    Published: 15 Nov 2016
    8.4
    High

    CVE-2016-0909

    Last Modified: 12 Apr 2025

    EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to potentially be compromised by malicious users.

    Published: 15 Nov 2016
    6.4
    Medium

    CVE-2016-7165

    Last Modified: 12 Apr 2025

    A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 V5.X (All versions < V5.5 SP4 HF11), SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced (All versions < V14), SIMATIC WinCC (TIA Portal) Professional V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) Professional V14 (All versions < V14 SP1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1), SIMATIC WinCC V7.0 SP2 and earlier versions (All versions < V7.0 SP2 Upd 12), SIMATIC WinCC V7.0 SP3 (All versions < V7.0 SP3 Upd 8), SIMATIC WinCC V7.2 (All versions < V7.2 Upd 14), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 11), SIMATIC WinCC V7.4 (All versions < V7.4 SP1), SIMIT V9.0 (All versions < V9.0 SP1), SINEMA Remote Connect Client (All versions < V1.0 SP3), SINEMA Server (All versions < V13 SP2), SOFTNET Security Client V5.0 (All versions), Security Configuration Tool (SCT) (All versions < V4.3 HF1), TeleControl Server Basic (All versions < V3.0 SP2), WinAC RTX 2010 SP2 (All versions), WinAC RTX F 2010 SP2 (All versions). Unquoted service paths could allow local Microsoft Windows operating system users to escalate their privileges if the affected products are not installed under their default path ("C:\Program Files\*" or the localized equivalent).

    Published: 15 Nov 2016
    8.4
    High

    CVE-2016-8661

    Last Modified: 12 Apr 2025

    Little Snitch version 3.0 through 3.6.1 suffer from a buffer overflow vulnerability that could be locally exploited which could lead to an escalation of privileges (EoP) and unauthorised ring0 access to the operating system. The buffer overflow is related to insufficient checking of parameters to the "OSMalloc" and "copyin" kernel API calls.

    Published: 15 Nov 2016
    9.8
    Critical

    CVE-2016-9287

    Last Modified: 12 Apr 2025

    In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

    Published: 15 Nov 2016
    7.5
    High

    CVE-2016-9446

    Last Modified: 17 Mar 2026

    The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.

    Published: 15 Nov 2016
    7.5
    High

    CVE-2016-9445

    Last Modified: 17 Mar 2026

    Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values, which triggers a buffer overflow.

    Published: 15 Nov 2016
    5.9
    Medium

    CVE-2016-9074

    Last Modified: 25 Nov 2025

    An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published: 15 Nov 2016
    8.6
    High

    CVE-2016-4331

    Last Modified: 12 Apr 2025

    When decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is within the bounds of the size leading to arbitrary code execution.

    Published: 15 Nov 2016
    8.6
    High

    CVE-2016-4332

    Last Modified: 12 Apr 2025

    The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative structure and then assign to fields that aren't supported by the message type and the library will write outside the bounds of the heap buffer. This can lead to code execution under the context of the library.

    Published: 15 Nov 2016
    5.5
    Medium

    CVE-2016-8646

    Last Modified: 12 Apr 2025

    The hash_accept function in crypto/algif_hash.c in the Linux kernel before 4.3.6 allows local users to cause a denial of service (OOPS) by attempting to trigger use of in-kernel hash algorithms for a socket that has received zero bytes of data.

    Published: 15 Nov 2016
    8.6
    High

    CVE-2016-4330

    Last Modified: 12 Apr 2025

    In the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the space allocated for it, a heap-based buffer overflow will occur, potentially leading to arbitrary code execution.

    Published: 15 Nov 2016
    5.3
    Medium

    CVE-2016-9071

    Last Modified: 21 Nov 2024

    Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    5.9
    Medium

    CVE-2016-1249

    Last Modified: 20 Apr 2025

    The DBD::mysql module before 4.039 for Perl, when using server-side prepared statement support, allows attackers to cause a denial of service (out-of-bounds read) via vectors involving an unaligned number of placeholders in WHERE condition and output fields in SELECT expression.

    Published: 15 Nov 2016
    6.5
    Medium

    CVE-2016-9067

    Last Modified: 21 Nov 2024

    Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016