CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2016-10208

    Last Modified: 20 Apr 2025

    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.

    Published: 15 Nov 2016
    6.1
    Medium

    CVE-2016-10365

    Last Modified: 20 Apr 2025

    Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link in the Kibana domain that redirects to an arbitrary website.

    Published: 15 Nov 2016
    8.6
    High

    CVE-2016-4333

    Last Modified: 12 Apr 2025

    The HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said array allowing a value within the file to modify the loop's terminator. Due to this, an aggressor can cause the loop's index to point outside the bounds of the array when initializing it.

    Published: 15 Nov 2016
    9.8
    Critical

    CVE-2016-5289

    Last Modified: 21 Nov 2024

    Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    6.5
    Medium

    CVE-2016-5292

    Last Modified: 21 Nov 2024

    During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    5.5
    Medium

    CVE-2016-8650

    Last Modified: 12 Apr 2025

    The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows local users to cause a denial of service (stack memory corruption and panic) via an add_key system call for an RSA key with a zero exponent.

    Published: 15 Nov 2016
    9.8
    Critical

    CVE-2016-9063

    Last Modified: 21 Nov 2024

    An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    7.5
    High

    CVE-2016-9068

    Last Modified: 21 Nov 2024

    A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    7.8
    High

    CVE-2016-9069

    Last Modified: 21 Nov 2024

    A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    8
    High

    CVE-2016-9070

    Last Modified: 21 Nov 2024

    A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    7.5
    High

    CVE-2016-9073

    Last Modified: 21 Nov 2024

    WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    9.8
    Critical

    CVE-2016-9075

    Last Modified: 21 Nov 2024

    An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    5.9
    Medium

    CVE-2016-9076

    Last Modified: 21 Nov 2024

    An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    7
    High

    CVE-2016-9077

    Last Modified: 21 Nov 2024

    Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.

    Published: 15 Nov 2016
    6.5
    Medium

    CVE-2016-9629

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 15 Nov 2016
    7.5
    High

    CVE-2016-9918

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash.

    Published: 15 Nov 2016
    8.8
    High

    CVE-2016-8906

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

    Published: 14 Nov 2016
    8.8
    High

    CVE-2016-8907

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

    Published: 14 Nov 2016
    9.8
    Critical

    CVE-2016-8902

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.

    Published: 14 Nov 2016
    8.8
    High

    CVE-2016-8903

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

    Published: 14 Nov 2016
    8.8
    High

    CVE-2016-8904

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

    Published: 14 Nov 2016
    8.8
    High

    CVE-2016-8905

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the sort parameter.

    Published: 14 Nov 2016
    8.8
    High

    CVE-2016-8908

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL commands via the orderby parameter.

    Published: 14 Nov 2016
    7.8
    High

    CVE-2016-9447

    Last Modified: 17 Mar 2026

    The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibly execute arbitrary code via a crafted NSF music file.

    Published: 14 Nov 2016
    6.8
    Medium

    CVE-2016-4484

    Last Modified: 20 Apr 2025

    The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password.

    Published: 14 Nov 2016
    9.8
    Critical

    CVE-2016-9941

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message containing a subrectangle outside of the client drawing area.

    Published: 14 Nov 2016
    9.8
    Critical

    CVE-2016-9942

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.

    Published: 14 Nov 2016
    7.5
    High

    CVE-2016-9917

    Last Modified: 12 Apr 2025

    In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash.

    Published: 14 Nov 2016
    6.5
    Medium

    CVE-2016-9627

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (heap buffer overflow and crash) via a crafted HTML page.

    Published: 13 Nov 2016
    6.5
    Medium

    CVE-2016-9628

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 13 Nov 2016
    7.5
    High

    CVE-2016-9296

    Last Modified: 12 Apr 2025

    A null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable folders.PackPositions in function CInArchive::ReadAndDecodePackedStreams in CPP/7zip/Archive/7z/7zIn.cpp, as used in the 7z.so library and in 7z applications, will cause a crash and a denial of service when decoding malformed 7z files.

    Published: 12 Nov 2016
    5.9
    Medium

    CVE-2016-10027

    Last Modified: 20 Apr 2025

    Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.

    Published: 12 Nov 2016
    5.5
    Medium

    CVE-2016-9557

    Last Modified: 20 Apr 2025

    Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 12 Nov 2016
    7.5
    High

    CVE-2016-9294

    Last Modified: 12 Apr 2025

    Artifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduct "denial of service (application crash)" attacks by using the "malformed labeled break/continue in JavaScript" approach, related to a "NULL pointer dereference" issue affecting the jscompile.c component.

    Published: 12 Nov 2016
    5.5
    Medium

    CVE-2016-9317

    Last Modified: 20 Apr 2025

    The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image.

    Published: 12 Nov 2016
    5.5
    Medium

    CVE-2016-9395

    Last Modified: 20 Apr 2025

    The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.

    Published: 12 Nov 2016
    9.8
    Critical

    CVE-2016-9288

    Last Modified: 12 Apr 2025

    In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1.

    Published: 11 Nov 2016
    5.3
    Medium

    CVE-2016-9284

    Last Modified: 12 Apr 2025

    getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.

    Published: 11 Nov 2016
    7.5
    High

    CVE-2016-9282

    Last Modified: 12 Apr 2025

    SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_string parameter.

    Published: 11 Nov 2016
    7.5
    High

    CVE-2016-9283

    Last Modified: 12 Apr 2025

    SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related to a "sef URL" issue.

    Published: 11 Nov 2016
    5.3
    Medium

    CVE-2016-9286

    Last Modified: 12 Apr 2025

    framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI.

    Published: 11 Nov 2016
    5.3
    Medium

    CVE-2016-9285

    Last Modified: 12 Apr 2025

    framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue.

    Published: 11 Nov 2016
    7.5
    High

    CVE-2016-9277

    Last Modified: 12 Apr 2025

    Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors involving APIs and an activity that computes an out-of-bounds array index, aka SVE-2016-6906.

    Published: 11 Nov 2016
    7.8
    High

    CVE-2016-9274

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.

    Published: 11 Nov 2016
    9.1
    Critical

    CVE-2016-9272

    Last Modified: 12 Apr 2025

    A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

    Published: 11 Nov 2016
    5.5
    Medium

    CVE-2016-9532

    Last Modified: 20 Apr 2025

    Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tif file.

    Published: 11 Nov 2016
    9.8
    Critical

    CVE-2016-9299

    Last Modified: 20 Apr 2025

    The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

    Published: 11 Nov 2016
    7.2
    High

    CVE-2016-9268

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension, and then accessing it via unspecified vectors.

    Published: 10 Nov 2016
    6.1
    Medium

    CVE-2016-7146

    Last Modified: 12 Apr 2025

    MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) component.

    Published: 10 Nov 2016
    6.1
    Medium

    CVE-2016-7148

    Last Modified: 12 Apr 2025

    MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.

    Published: 10 Nov 2016