CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-10251

    Last Modified: 20 Apr 2025

    Integer overflow in the jpc_pi_nextcprl function in jpc_t2cod.c in JasPer before 1.900.20 allows remote attackers to have unspecified impact via a crafted file, which triggers use of an uninitialized value.

    Published: 4 Nov 2016
    9.8
    Critical

    CVE-2016-9176

    Last Modified: 12 Apr 2025

    Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers able to inject arguments to these binaries to execute code.

    Published: 4 Nov 2016
    8.8
    High

    CVE-2017-0362

    Last Modified: 21 Nov 2024

    Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw where the "Mark all pages visited" on the watchlist does not require a CSRF token.

    Published: 4 Nov 2016
    7.5
    High

    CVE-2016-9177

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 4 Nov 2016
    6.1
    Medium

    CVE-2016-6429

    Last Modified: 12 Apr 2025

    A vulnerability in the web framework code of the Cisco IP Interoperability and Collaboration System (IPICS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. More Information: CSCva47092. Known Affected Releases: 4.10(1).

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-6441

    Last Modified: 12 Apr 2025

    A vulnerability in the Transaction Language 1 (TL1) code of Cisco ASR 900 Series routers could allow an unauthenticated, remote attacker to cause a reload of, or remotely execute code on, the affected system. This vulnerability affects Cisco ASR 900 Series Aggregation Services Routers (ASR902, ASR903, and ASR907) that are running the following releases of Cisco IOS XE Software: 3.17.0S 3.17.1S 3.17.2S 3.18.0S 3.18.1S. More Information: CSCuy15175. Known Affected Releases: 15.6(1)S 15.6(2)S. Known Fixed Releases: 15.6(1)S2.12 15.6(1.17)S0.41 15.6(1.17)SP 15.6(2)SP 16.4(0.183) 16.5(0.10).

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-6448

    Last Modified: 12 Apr 2025

    A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to Release 2.0.3, Acano Server releases 1.9.x prior to Release 1.9.5, Acano Server releases 1.8.x prior to Release 1.8.17. More Information: CSCva76004. Known Affected Releases: 1.8.x 1.92.0.

    Published: 3 Nov 2016
    7.8
    High

    CVE-2016-6430

    Last Modified: 12 Apr 2025

    A vulnerability in the command-line interface of the Cisco IP Interoperability and Collaboration System (IPICS) could allow an authenticated, local attacker to elevate the privilege level associated with their session. More Information: CSCva38636. Known Affected Releases: 4.10(1). Known Fixed Releases: 5.0(1).

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-6447

    Last Modified: 12 Apr 2025

    A vulnerability in Cisco Meeting Server and Meeting App could allow an unauthenticated, remote attacker to execute arbitrary code on an affected system. This vulnerability affects the following products: Cisco Meeting Server releases prior to 2.0.1, Acano Server releases prior to 1.8.16 and prior to 1.9.3, Cisco Meeting App releases prior to 1.9.8, Acano Meeting Apps releases prior to 1.8.35. More Information: CSCva75942 CSCvb67878. Known Affected Releases: 1.81.92.0.

    Published: 3 Nov 2016
    6.1
    Medium

    CVE-2016-6451

    Last Modified: 12 Apr 2025

    Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCut43061 CSCut43066 CSCut43736 CSCut43738 CSCut43741 CSCut43745 CSCut43748 CSCut43751 CSCut43756 CSCut43759 CSCut43764 CSCut43766. Known Affected Releases: 10.6.

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-6452

    Last Modified: 12 Apr 2025

    A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. Cisco Prime Home versions 5.1.1.6 and earlier and 5.2.2.2 and earlier have been confirmed to be vulnerable. Cisco Prime Home versions 6.0 and later are not vulnerable. More Information: CSCvb71732. Known Affected Releases: 5.0 5.0(1) 5.0(1.1) 5.0(1.2) 5.0(2) 5.15.1(0) 5.1(1) 5.1(1.3) 5.1(1.4) 5.1(1.5) 5.1(1.6) 5.1(2) 5.1(2.1) 5.1(2.3) 5.25.2(0.1) 5.2(1.0) 5.2(1.2) 5.2(2.0) 5.2(2.1) 5.2(2.2).

    Published: 3 Nov 2016
    7.3
    High

    CVE-2016-6453

    Last Modified: 12 Apr 2025

    A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary SQL commands on the database. More Information: CSCva46542. Known Affected Releases: 1.3(0.876).

    Published: 3 Nov 2016
    6.5
    Medium

    CVE-2016-6454

    Last Modified: 12 Apr 2025

    A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfillment application could allow an unauthenticated, remote attacker to execute unwanted actions. More Information: CSCva54241. Known Affected Releases: 11.5(1). Known Fixed Releases: 11.5(0.98000.216).

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-6455

    Last Modified: 12 Apr 2025

    A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote attacker to cause a subset of the subscriber sessions to be disconnected, resulting in a partial denial of service (DoS) condition. This vulnerability affects Cisco ASR 5500 devices with Data Processing Card 2 (DPC2) running StarOS 18.0 or later. More Information: CSCvb12081. Known Affected Releases: 18.7.4 19.5.0 20.0.2.64048 20.2.3 21.0.0. Known Fixed Releases: 18.7.4 18.7.4.65030 18.8.M0.65044 19.5.0 19.5.0.65092 19.5.M0.65023 19.5.M0.65050 20.2.3 20.2.3.64982 20.2.3.65017 20.2.a4.65307 20.3.M0.64984 20.3.M0.65029 20.3.M0.65037 20.3.M0.65071 20.3.T0.64985 20.3.T0.65031 20.3.T0.65043 20.3.T0.65067 21.0.0 21.0.0.65256 21.0.M0.64922 21.0.M0.64983 21.0.M0.65140 21.0.V0.65150 21.1.A0.64932 21.1.A0.64987 21.1.A0.65145 21.1.PP0.65270 21.1.R0.65130 21.1.R0.65135 21.1.R0.65154 21.1.VC0.65203 21.2.A0.65147.

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-7453

    Last Modified: 12 Apr 2025

    The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-7095

    Last Modified: 12 Apr 2025

    Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.

    Published: 3 Nov 2016
    8.8
    High

    CVE-2015-8968

    Last Modified: 12 Apr 2025

    git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can instruct a user to run a recursive clone from a repository they control, they can get a client to run an arbitrary shell command. Alternately, if an attacker can MITM an unencrypted git clone, they could exploit this. The ext command will be run if the repository is recursively cloned or if submodules are updated. This attack works when cloning both local and remote repositories.

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2015-8969

    Last Modified: 12 Apr 2025

    git-fastclone before 1.0.5 passes user modifiable strings directly to a shell command. An attacker can execute malicious commands by modifying the strings that are passed as arguments to "cd " and "git clone " commands in the library.

    Published: 3 Nov 2016
    5.5
    Medium

    CVE-2016-4025

    Last Modified: 12 Apr 2025

    Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection Suite Plus v8.x.x, File Server Security v8.x.x, and Email Server Security v8.x.x allow attackers to bypass the DeepScreen feature via a DeviceIoControl call.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-7160

    Last Modified: 12 Apr 2025

    A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248.

    Published: 3 Nov 2016
    9.8
    Critical

    CVE-2016-7402

    Last Modified: 12 Apr 2025

    SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-7452

    Last Modified: 12 Apr 2025

    The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-9135

    Last Modified: 12 Apr 2025

    Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-9136

    Last Modified: 12 Apr 2025

    Artifex Software, Inc. MuJS before a0ceaf5050faf419401fe1b83acfa950ec8a8a89 allows context-dependent attackers to obtain sensitive information by using the "crafted JavaScript" approach, related to a "Buffer Over-read" issue.

    Published: 3 Nov 2016
    6.5
    Medium

    CVE-2016-9086

    Last Modified: 12 Apr 2025

    GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature allows a user to export and then re-import their projects as tape archive files (tar). All GitLab versions prior to 8.13.0 restricted this feature to administrators only. Starting with version 8.13.0 this feature was made available to all users. This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain secret tokens used by the GitLab service to authenticate users. GitLab CE and EE versions 8.13.0 through 8.13.2, 8.12.0 through 8.12.7, 8.11.0 through 8.11.10, 8.10.0 through 8.10.12, and 8.9.0 through 8.9.11 are affected.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-9134

    Last Modified: 12 Apr 2025

    Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure.

    Published: 3 Nov 2016
    6.1
    Medium

    CVE-2016-8634

    Last Modified: 21 Nov 2024

    A vulnerability was found in foreman 1.14.0. When creating an organization or location in Foreman, if the name contains HTML then the second step of the wizard (/organizations/id/step2) will render the HTML. This occurs in the alertbox on the page. The result is a stored XSS attack if an organization/location with HTML in the name is created, then a user is linked directly to this URL.

    Published: 3 Nov 2016
    8.8
    High

    CVE-2016-7035

    Last Modified: 21 Nov 2024

    An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to execute a script as root and thereby gain root access on the machine.

    Published: 3 Nov 2016
    7.5
    High

    CVE-2016-9179

    Last Modified: 12 Apr 2025

    lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

    Published: 3 Nov 2016
    4.3
    Medium

    CVE-2016-9185

    Last Modified: 12 Apr 2025

    In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

    Published: 3 Nov 2016
    7.8
    High

    CVE-2016-9644

    Last Modified: 12 Apr 2025

    The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel 4.4.22 through 4.4.28 contains extended asm statements that are incompatible with the exception table, which allows local users to obtain root access on non-SMEP platforms via a crafted application. NOTE: this vulnerability exists because of incorrect backporting of the CVE-2016-9178 patch to older kernels.

    Published: 3 Nov 2016
    6.5
    Medium

    CVE-2016-9573

    Last Modified: 21 Nov 2024

    An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.

    Published: 2 Nov 2016
    5.5
    Medium

    CVE-2016-10068

    Last Modified: 20 Apr 2025

    The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted XML file.

    Published: 2 Nov 2016
    8
    High

    CVE-2016-7070

    Last Modified: 21 Nov 2024

    A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

    Published: 2 Nov 2016
    3.7
    Low

    CVE-2016-8616

    Last Modified: 21 Nov 2024

    A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections. This means that if an unused connection with proper credentials exists for a protocol that has connection-scoped credentials, an attacker can cause that connection to be reused if s/he knows the case-insensitive version of the correct password.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8618

    Last Modified: 21 Nov 2024

    The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8619

    Last Modified: 21 Nov 2024

    The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8625

    Last Modified: 21 Nov 2024

    curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowingly issue network transfer requests to the wrong host.

    Published: 2 Nov 2016
    5.5
    Medium

    CVE-2016-8630

    Last Modified: 12 Apr 2025

    The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8621

    Last Modified: 16 Apr 2026

    The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8624

    Last Modified: 16 Apr 2026

    curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have security implications if you for example use an URL parser that follows the RFC to check for allowed domains before using curl to request them.

    Published: 2 Nov 2016
    3.3
    Low

    CVE-2016-8623

    Last Modified: 16 Apr 2026

    A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information disclosure.

    Published: 2 Nov 2016
    3.3
    Low

    CVE-2016-8617

    Last Modified: 16 Apr 2026

    The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as input via `CURLOPT_USERNAME`.

    Published: 2 Nov 2016
    5.3
    Medium

    CVE-2016-8615

    Last Modified: 16 Apr 2026

    A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.

    Published: 2 Nov 2016
    3.7
    Low

    CVE-2016-8622

    Last Modified: 15 Apr 2026

    The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just truncated or both truncated and turned negative. That could then lead to libcurl writing outside of its heap based buffer.

    Published: 2 Nov 2016
    6.5
    Medium

    CVE-2016-8620

    Last Modified: 15 Apr 2026

    The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

    Published: 2 Nov 2016
    9.8
    Critical

    CVE-2016-9013

    Last Modified: 12 Apr 2025

    Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

    Published: 1 Nov 2016
    8.8
    High

    CVE-2016-5198

    Last Modified: 21 Apr 2026

    V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.

    Published: 1 Nov 2016
    4
    Medium

    CVE-2016-2121

    Last Modified: 21 Nov 2024

    A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system information.

    Published: 1 Nov 2016
    7.6
    High

    CVE-2016-8628

    Last Modified: 21 Nov 2024

    Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker with the ability to create special variables on the controller could execute arbitrary commands on Ansible clients as the user Ansible runs as.

    Published: 1 Nov 2016