CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-7390

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000194 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-7391

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds check can allow a user to write to kernel memory, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8806

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x5000027 where a pointer passed from an user to the driver is used without validation, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-8812

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8810

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8811

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-3161

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-3161 ID is for the GameStream unquoted service path.

    Published: 8 Nov 2016
    7.5
    High

    CVE-2016-4959

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of service. A successful exploit of a vulnerable system will result in a kernel null pointer dereference, causing a blue screen crash.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8805

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000014 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8807

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed from an user to the driver is used without validation as the size input to memcpy() causing a stack buffer overflow, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    7.8
    High

    CVE-2016-8809

    Last Modified: 12 Apr 2025

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

    Published: 8 Nov 2016
    6.1
    Medium

    CVE-2016-7851

    Last Modified: 12 Apr 2025

    Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7857

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    6.5
    Medium

    CVE-2016-9911

    Last Modified: 12 Apr 2025

    Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.

    Published: 8 Nov 2016
    4.7
    Medium

    CVE-2016-10741

    Last Modified: 21 Nov 2024

    In the Linux kernel before 4.9.3, fs/xfs/xfs_aops.c allows local users to cause a denial of service (system crash) because there is a race condition between direct and memory-mapped I/O (associated with a hole) that is handled with BUG_ON instead of an I/O failure.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7859

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7860

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7861

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7864

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7865

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7858

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7862

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    8.8
    High

    CVE-2016-7863

    Last Modified: 12 Apr 2025

    Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 8 Nov 2016
    6.8
    Medium

    CVE-2016-9111

    Last Modified: 12 Apr 2025

    Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to provide us with information that would allow us to confirm the behaviour and, despite extensive investigation on test deployments of supported products, we were unable to reproduce the behaviour as he described. The researcher has also, despite additional requests for information, ceased to respond to us."

    Published: 7 Nov 2016
    8.8
    High

    CVE-2016-9242

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter.

    Published: 7 Nov 2016
    7.5
    High

    CVE-2016-9297

    Last Modified: 20 Apr 2025

    The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII tag values.

    Published: 7 Nov 2016
    7.8
    High

    CVE-2016-8632

    Last Modified: 12 Apr 2025

    The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a denial of service (heap-based buffer overflow) by leveraging the CAP_NET_ADMIN capability.

    Published: 7 Nov 2016
    5
    Medium

    CVE-2016-8637

    Last Modified: 21 Nov 2024

    A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.

    Published: 7 Nov 2016
    5.5
    Medium

    CVE-2016-9273

    Last Modified: 20 Apr 2025

    tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstrips in TIFF_STRIPCHOP mode.

    Published: 7 Nov 2016
    6.5
    Medium

    CVE-2016-9626

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

    Published: 7 Nov 2016
    3.5
    Low

    CVE-2016-7061

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive information.

    Published: 7 Nov 2016
    6.5
    Medium

    CVE-2016-9624

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 7 Nov 2016
    6.5
    Medium

    CVE-2016-9625

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

    Published: 7 Nov 2016
    6.5
    Medium

    CVE-2016-9907

    Last Modified: 12 Apr 2025

    Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.

    Published: 7 Nov 2016
    6.8
    Medium

    CVE-2016-8633

    Last Modified: 12 Apr 2025

    drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.

    Published: 6 Nov 2016
    6.5
    Medium

    CVE-2016-9623

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 6 Nov 2016
    6.5
    Medium

    CVE-2016-9622

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 6 Nov 2016
    5.5
    Medium

    CVE-2016-9262

    Last Modified: 20 Apr 2025

    Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

    Published: 6 Nov 2016
    7.5
    High

    CVE-2016-9243

    Last Modified: 20 Apr 2025

    HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

    Published: 5 Nov 2016
    4.7
    Medium

    CVE-2017-5969

    Last Modified: 20 Apr 2025

    libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser.

    Published: 5 Nov 2016
    5.5
    Medium

    CVE-2016-9191

    Last Modified: 12 Apr 2025

    The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial of service (system hang) by leveraging access to a container environment for executing a crafted application, as demonstrated by trinity.

    Published: 5 Nov 2016
    9.8
    Critical

    CVE-2016-8869

    Last Modified: 12 Apr 2025

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.

    Published: 4 Nov 2016
    8.1
    High

    CVE-2016-8870

    Last Modified: 12 Apr 2025

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

    Published: 4 Nov 2016
    7.5
    High

    CVE-2016-9183

    Last Modified: 12 Apr 2025

    In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of ' or " characters. Impact is Information Disclosure.

    Published: 4 Nov 2016
    7.5
    High

    CVE-2016-9182

    Last Modified: 12 Apr 2025

    Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits undefined actions to execute by default, so an attacker can use a capitalized method name to bypass the permission check, e.g., controller=expHTMLEditor&action=preview&editor=ckeditor and controller=expHTMLEditor&action=Preview&editor=ckeditor. An anonymous user will be rejected for the former but can access the latter.

    Published: 4 Nov 2016
    8.8
    High

    CVE-2016-9186

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

    Published: 4 Nov 2016
    8.8
    High

    CVE-2016-9187

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.

    Published: 4 Nov 2016
    6.1
    Medium

    CVE-2016-9188

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML via the s_additionalhtmlhead, s_additionalhtmltopofbody, and s_additionalhtmlfooter parameters.

    Published: 4 Nov 2016
    7.5
    High

    CVE-2016-9184

    Last Modified: 12 Apr 2025

    In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

    Published: 4 Nov 2016
    9.8
    Critical

    CVE-2016-9535

    Last Modified: 29 May 2026

    tif_predict.h and tif_predict.c in libtiff 4.0.6 have assertions that can lead to assertion failures in debug mode, or buffer overflows in release mode, when dealing with unusual tile size like YCbCr with subsampling. Reported as MSVR 35105, aka "Predictor heap-buffer-overflow."

    Published: 4 Nov 2016