CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-9117

    Last Modified: 12 Apr 2025

    NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

    Published: 27 Oct 2016
    5.3
    Medium

    CVE-2016-9118

    Last Modified: 12 Apr 2025

    Heap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.

    Published: 27 Oct 2016
    5.3
    Medium

    CVE-2016-6794

    Last Modified: 20 Apr 2025

    When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to 6.0.45 the system property replacement feature for configuration files could be used by a malicious web application to bypass the SecurityManager and read system properties that should not be visible.

    Published: 27 Oct 2016
    7.5
    High

    CVE-2016-6796

    Last Modified: 20 Apr 2025

    A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.

    Published: 27 Oct 2016
    7.5
    High

    CVE-2016-6797

    Last Modified: 20 Apr 2025

    The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.

    Published: 27 Oct 2016
    5.3
    Medium

    CVE-2016-8501

    Last Modified: 12 Apr 2025

    Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled.

    Published: 26 Oct 2016
    6.1
    Medium

    CVE-2016-8506

    Last Modified: 12 Apr 2025

    XSS in Yandex Browser Translator in Yandex browser for desktop for versions from 15.12 to 16.2 could be used by remote attacker for evaluation arbitrary javascript code.

    Published: 26 Oct 2016
    4.3
    Medium

    CVE-2016-8504

    Last Modified: 12 Apr 2025

    CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

    Published: 26 Oct 2016
    6.1
    Medium

    CVE-2016-8505

    Last Modified: 12 Apr 2025

    XSS in Yandex Browser BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary javascript code.

    Published: 26 Oct 2016
    7.3
    High

    CVE-2016-8502

    Last Modified: 12 Apr 2025

    Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.

    Published: 26 Oct 2016
    7.3
    High

    CVE-2016-8503

    Last Modified: 12 Apr 2025

    Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.

    Published: 26 Oct 2016
    Unknown

    CVE-2016-8338

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5314. Reason: This candidate is a reservation duplicate of CVE-2016-5314. Notes: All CVE users should reference CVE-2016-5314 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Oct 2016
    8.8
    High

    CVE-2016-7855

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

    Published: 26 Oct 2016
    4.9
    Medium

    CVE-2016-8647

    Last Modified: 21 Nov 2024

    An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

    Published: 26 Oct 2016
    9.8
    Critical

    CVE-2016-5405

    Last Modified: 20 Apr 2025

    389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to obtain user passwords.

    Published: 26 Oct 2016
    7
    High

    CVE-2016-7032

    Last Modified: 20 Apr 2025

    sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via an application that calls the (1) system or (2) popen function.

    Published: 26 Oct 2016
    6.4
    Medium

    CVE-2016-7076

    Last Modified: 21 Nov 2024

    sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

    Published: 26 Oct 2016
    4.8
    Medium

    CVE-2016-8285

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway.

    Published: 25 Oct 2016
    4.2
    Medium

    CVE-2016-8292

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5479

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, and 12.0.1 allows remote authenticated users to affect confidentiality via vectors related to INFRA.

    Published: 25 Oct 2016
    7.5
    High

    CVE-2016-5495

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to EUL Code & Schema.

    Published: 25 Oct 2016
    8.8
    High

    CVE-2016-5523

    Last Modified: 8 May 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AutoVue Java Applet.

    Published: 25 Oct 2016
    5.9
    Medium

    CVE-2016-5527

    Last Modified: 8 May 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2016-5524.

    Published: 25 Oct 2016
    6.1
    Medium

    CVE-2016-5529

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5530 and CVE-2016-8293.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5558

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5574, CVE-2016-5577, CVE-2016-5578, CVE-2016-5579, and CVE-2016-5588.

    Published: 25 Oct 2016
    7.7
    High

    CVE-2016-5565

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality via vectors related to OPERA.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5579

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5574, CVE-2016-5577, CVE-2016-5578, and CVE-2016-5588.

    Published: 25 Oct 2016
    6.5
    Medium

    CVE-2016-5585

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Interaction Center Intelligence component in Oracle E-Business Suite 12.1.1 through 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5591

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5593.

    Published: 25 Oct 2016
    8.1
    High

    CVE-2016-5619

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5620.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5621

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 and 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different vulnerability than CVE-2016-5603.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-8291

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform.

    Published: 25 Oct 2016
    5.7
    Medium

    CVE-2016-5537

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information is from the October 2016 CPU. Oracle has not commented on third-party claims that this issue is a directory traversal vulnerability which allows local users with certain permissions to write to arbitrary files and consequently gain privileges via a .. (dot dot) in a archive entry in a ZIP file imported as a project.

    Published: 25 Oct 2016
    4.1
    Medium

    CVE-2016-5559

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect integrity via vectors related to Kernel.

    Published: 25 Oct 2016
    5.4
    Medium

    CVE-2016-5560

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to OpenUI.

    Published: 25 Oct 2016
    7.9
    High

    CVE-2016-5563

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote administrators to affect confidentiality, integrity, and availability via vectors related to OPERA.

    Published: 25 Oct 2016
    5.3
    Medium

    CVE-2016-5566

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5574

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5577, CVE-2016-5578, CVE-2016-5579, and CVE-2016-5588.

    Published: 25 Oct 2016
    9.6
    Critical

    CVE-2016-5580

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Secure Global Desktop component in Oracle Virtualization 4.7 and 5.2 allows remote authenticated users to affect confidentiality and availability via vectors through Web Services.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5586

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Email Center component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5588

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5574, CVE-2016-5577, CVE-2016-5578, and CVE-2016-5579.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5592

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5595.

    Published: 25 Oct 2016
    5.6
    Medium

    CVE-2016-5598

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5603

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality via vectors related to INFRA, a different vulnerability than CVE-2016-5621.

    Published: 25 Oct 2016
    6.3
    Medium

    CVE-2016-5604

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563.

    Published: 25 Oct 2016
    6.8
    Medium

    CVE-2016-5610

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core.

    Published: 25 Oct 2016
    2.8
    Low

    CVE-2016-5480

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect integrity via vectors related to Bash.

    Published: 25 Oct 2016
    3.7
    Low

    CVE-2016-5481

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows remote attackers to affect confidentiality via vectors related to Core Services.

    Published: 25 Oct 2016
    5.5
    Medium

    CVE-2016-5486

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality via vectors related to Core Services.

    Published: 25 Oct 2016
    5.3
    Medium

    CVE-2016-5487

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 25 Oct 2016