CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2016-8614

    Last Modified: 21 Nov 2024

    A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct key.

    Published: 1 Nov 2016
    7.5
    High

    CVE-2016-8864

    Last Modified: 12 Apr 2025

    named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.

    Published: 1 Nov 2016
    3.3
    Low

    CVE-2016-9908

    Last Modified: 12 Apr 2025

    Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

    Published: 1 Nov 2016
    6.5
    Medium

    CVE-2016-9845

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents of the host memory bytes.

    Published: 1 Nov 2016
    6.3
    Medium

    CVE-2016-8631

    Last Modified: 21 Nov 2024

    The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.

    Published: 1 Nov 2016
    8.1
    High

    CVE-2016-9014

    Last Modified: 12 Apr 2025

    Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.

    Published: 1 Nov 2016
    6.5
    Medium

    CVE-2016-9846

    Last Modified: 12 Apr 2025

    QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory bytes, resulting in DoS for a host.

    Published: 1 Nov 2016
    7.5
    High

    CVE-2016-8203

    Last Modified: 12 Apr 2025

    A memory corruption in the IPsec code path of Brocade NetIron OS on Brocade MLXs 5.8.00 through 5.8.00e, 5.9.00 through 5.9.00bd, 6.0.00, and 6.0.00a images could allow attackers to cause a denial of service (line card reset) via certain constructed IPsec control packets.

    Published: 31 Oct 2016
    8.6
    High

    CVE-2016-7964

    Last Modified: 12 Apr 2025

    The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-7991

    Last Modified: 12 Apr 2025

    On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.

    Published: 31 Oct 2016
    9.8
    Critical

    CVE-2016-7990

    Last Modified: 12 Apr 2025

    On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS messages) leading to a heap corruption that can result in Denial of Service and potentially remote code execution, a subset of SVE-2016-6542.

    Published: 31 Oct 2016
    5.3
    Medium

    CVE-2016-8875

    Last Modified: 12 Apr 2025

    The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."

    Published: 31 Oct 2016
    7.8
    High

    CVE-2016-8856

    Last Modified: 12 Apr 2025

    Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-8876

    Last Modified: 12 Apr 2025

    Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF image embedded in the XFA stream in a PDF document, aka "Read Access Violation starting at FoxitReader."

    Published: 31 Oct 2016
    8.8
    High

    CVE-2016-8878

    Last Modified: 12 Apr 2025

    Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."

    Published: 31 Oct 2016
    6.5
    Medium

    CVE-2016-7965

    Last Modified: 12 Apr 2025

    DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if several domains are served by the same web server).

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-7988

    Last Modified: 12 Apr 2025

    On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar within the Android Framework, a subset of SVE-2016-6542.

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-7989

    Last Modified: 12 Apr 2025

    On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar. This causes the Android runtime to continually crash, rendering the device unusable until a factory reset is performed, a subset of SVE-2016-6542.

    Published: 31 Oct 2016
    8.8
    High

    CVE-2016-8877

    Last Modified: 12 Apr 2025

    Heap buffer overflow (Out-of-Bounds write) vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to execute arbitrary code via a crafted JPEG2000 image embedded in a PDF document, aka a "corrupted suffix pattern" issue.

    Published: 31 Oct 2016
    6.5
    Medium

    CVE-2016-8879

    Last Modified: 12 Apr 2025

    The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.

    Published: 31 Oct 2016
    9.8
    Critical

    CVE-2016-8704

    Last Modified: 20 Apr 2025

    An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

    Published: 31 Oct 2016
    5.5
    Medium

    CVE-2016-9298

    Last Modified: 20 Apr 2025

    Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image.

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-10149

    Last Modified: 20 Apr 2025

    XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request or response.

    Published: 31 Oct 2016
    9.8
    Critical

    CVE-2016-8705

    Last Modified: 20 Apr 2025

    Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

    Published: 31 Oct 2016
    8.1
    High

    CVE-2016-8706

    Last Modified: 20 Apr 2025

    An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.

    Published: 31 Oct 2016
    7.5
    High

    CVE-2016-9112

    Last Modified: 12 Apr 2025

    Floating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.

    Published: 29 Oct 2016
    5.7
    Medium

    CVE-2016-3060

    Last Modified: 12 Apr 2025

    Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

    Published: 29 Oct 2016
    5.4
    Medium

    CVE-2016-5920

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM Financial Transaction Manager (FTM) for ACH Services 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Oct 2016
    9.8
    Critical

    CVE-2016-7504

    Last Modified: 12 Apr 2025

    A use-after-free vulnerability was observed in Rp_toString function of Artifex Software, Inc. MuJS before 5c337af4b3df80cf967e4f9f6a21522de84b392a. A successful exploitation of this issue can lead to code execution or denial of service condition.

    Published: 29 Oct 2016
    9.8
    Critical

    CVE-2016-7505

    Last Modified: 12 Apr 2025

    A buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before 8c805b4eb19cf2af689c860b77e6111d2ee439d5. A successful exploitation of this issue can lead to code execution or denial of service condition.

    Published: 29 Oct 2016
    7.5
    High

    CVE-2016-7506

    Last Modified: 12 Apr 2025

    An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de840997f4a. A successful exploitation of this issue can lead to code execution or denial of service condition.

    Published: 29 Oct 2016
    9.8
    Critical

    CVE-2015-8972

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.

    Published: 29 Oct 2016
    3.7
    Low

    CVE-2016-1000346

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated. This can cause issues as invalid keys can be used to reveal details about the other party's private key where static Diffie-Hellman is in use. As of release 1.56 the key parameters are checked on agreement calculation.

    Published: 29 Oct 2016
    7.5
    High

    CVE-2016-6497

    Last Modified: 20 Apr 2025

    main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.

    Published: 29 Oct 2016
    7.5
    High

    CVE-2016-4395

    Last Modified: 12 Apr 2025

    HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

    Published: 28 Oct 2016
    7.5
    High

    CVE-2016-4396

    Last Modified: 12 Apr 2025

    HPE System Management Homepage before v7.6 allows remote attackers to have an unspecified impact via unknown vectors, related to a "Buffer Overflow" issue.

    Published: 28 Oct 2016
    5.4
    Medium

    CVE-2016-4393

    Last Modified: 12 Apr 2025

    HPE System Management Homepage before v7.6 allows "remote authenticated" attackers to obtain sensitive information via unspecified vectors, related to an "XSS" issue.

    Published: 28 Oct 2016
    6.5
    Medium

    CVE-2016-4394

    Last Modified: 12 Apr 2025

    HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.

    Published: 28 Oct 2016
    8.8
    High

    CVE-2016-8335

    Last Modified: 12 Apr 2025

    An exploitable stack based buffer overflow vulnerability exists in the ipNameAdd functionality of Iceni Argus Version 6.6.04 (Sep 7 2012) NK - Linux x64 and Version 6.6.04 (Nov 14 2014) NK - Windows x64. A specially crafted pdf file can cause a buffer overflow resulting in arbitrary code execution. An attacker can send/provide malicious pdf file to trigger this vulnerability.

    Published: 28 Oct 2016
    8.8
    High

    CVE-2016-8333

    Last Modified: 12 Apr 2025

    An exploitable stack-based buffer overflow vulnerability exists in the ipfSetColourStroke functionality of Iceni Argus version 6.6.04 A specially crafted pdf file can cause a buffer overflow resulting in arbitrary code execution. An attacker can provide a malicious pdf file to trigger this vulnerability.

    Published: 28 Oct 2016
    9.8
    Critical

    CVE-2016-8597

    Last Modified: 14 Aug 2025

    Buffer overflow in the csp_sfp_recv_fp in csp_sfp.c in the libcsp library v1.4 and earlier allows hostile components with network access to the SFP underlying network layers to execute arbitrary code via specially crafted SFP packets.

    Published: 28 Oct 2016
    7.5
    High

    CVE-2016-7919

    Last Modified: 12 Apr 2025

    Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.

    Published: 28 Oct 2016
    4
    Medium

    CVE-2016-8579

    Last Modified: 12 Apr 2025

    docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain.

    Published: 28 Oct 2016
    9.8
    Critical

    CVE-2016-8580

    Last Modified: 12 Apr 2025

    PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.

    Published: 28 Oct 2016
    9.8
    Critical

    CVE-2016-8596

    Last Modified: 14 Aug 2025

    Buffer overflow in the csp_can_process_frame in csp_if_can.c in the libcsp library v1.4 and earlier allows hostile components connected to the canbus to execute arbitrary code via a long csp packet.

    Published: 28 Oct 2016
    5.5
    Medium

    CVE-2016-9018

    Last Modified: 12 Apr 2025

    Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.

    Published: 28 Oct 2016
    8.8
    High

    CVE-2016-9028

    Last Modified: 12 Apr 2025

    Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.

    Published: 28 Oct 2016
    6.1
    Medium

    CVE-2016-8583

    Last Modified: 12 Apr 2025

    Multiple GET parameters in the vulnerability scan scheduler of AlienVault OSSIM and USM before 5.3.2 are vulnerable to reflected XSS.

    Published: 28 Oct 2016
    9.8
    Critical

    CVE-2016-8598

    Last Modified: 14 Aug 2025

    Buffer overflow in the zmq interface in csp_if_zmqhub.c in the libcsp library v1.4 and earlier allows hostile computers connected via a zmq interface to execute arbitrary code via a long packet.

    Published: 28 Oct 2016
    7.5
    High

    CVE-2016-8600

    Last Modified: 12 Apr 2025

    In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.

    Published: 28 Oct 2016