CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2016-5540

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Xstore Payment component in Oracle Retail Applications 1.x allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    7.8
    High

    CVE-2016-5544

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentiality, integrity, and availability via vectors related to Kernel/X86.

    Published: 25 Oct 2016
    9.1
    Critical

    CVE-2016-5555

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote administrators to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5557

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Advanced Pricing component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    3.1
    Low

    CVE-2016-5561

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect availability via vectors related to IKE.

    Published: 25 Oct 2016
    7.6
    High

    CVE-2016-5562

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    7.4
    High

    CVE-2016-5564

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to OPERA.

    Published: 25 Oct 2016
    6.5
    Medium

    CVE-2016-5567

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5571.

    Published: 25 Oct 2016
    5.4
    Medium

    CVE-2016-5569

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    6.5
    Medium

    CVE-2016-5570

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities.

    Published: 25 Oct 2016
    6.5
    Medium

    CVE-2016-5571

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 and 12.2.3 through 12.2.6 allows remote administrators to affect confidentiality and integrity via vectors related to AD Utilities, a different vulnerability than CVE-2016-5567.

    Published: 25 Oct 2016
    5.3
    Medium

    CVE-2016-5575

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Resources Module.

    Published: 25 Oct 2016
    5.5
    Medium

    CVE-2016-5576

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Kernel Zones.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5577

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5574, CVE-2016-5578, CVE-2016-5579, and CVE-2016-5588.

    Published: 25 Oct 2016
    8.6
    High

    CVE-2016-5578

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.5.1 through 8.5.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters, a different vulnerability than CVE-2016-5558, CVE-2016-5574, CVE-2016-5577, CVE-2016-5579, and CVE-2016-5588.

    Published: 25 Oct 2016
    6.6
    Medium

    CVE-2016-5581

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 25 Oct 2016
    5.3
    Medium

    CVE-2016-5583

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle One-to-One Fulfillment component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect integrity via unknown vectors.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5587

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5591 and CVE-2016-5593.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5589

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5593

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5587 and CVE-2016-5591.

    Published: 25 Oct 2016
    5
    Medium

    CVE-2016-5594

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, and 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to INFRA.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-5595

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5592.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5596

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 25 Oct 2016
    3.3
    Low

    CVE-2016-5615

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Lynx.

    Published: 25 Oct 2016
    9.1
    Critical

    CVE-2016-5599

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Advanced Supply Chain Planning component in Oracle Supply Chain Products Suite 12.2.3 through 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to MscObieeSrvlt.

    Published: 25 Oct 2016
    5.4
    Medium

    CVE-2016-5600

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise SCM Services Procurement component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 25 Oct 2016
    6.3
    Medium

    CVE-2016-5601

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows local users to affect confidentiality and integrity via vectors related to CIE Related Components.

    Published: 25 Oct 2016
    5.7
    Medium

    CVE-2016-5602

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.

    Published: 25 Oct 2016
    9.1
    Critical

    CVE-2016-5605

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.

    Published: 25 Oct 2016
    6.1
    Medium

    CVE-2016-5606

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Kernel Zones.

    Published: 25 Oct 2016
    8.8
    High

    CVE-2016-5607

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to INFRA.

    Published: 25 Oct 2016
    5.5
    Medium

    CVE-2016-5608

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5613.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5611

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality via vectors related to Core.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-5613

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5608.

    Published: 25 Oct 2016
    5.4
    Medium

    CVE-2016-5620

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5619.

    Published: 25 Oct 2016
    6.1
    Medium

    CVE-2016-5622

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote attackers to affect confidentiality and integrity via vectors related to INFRA.

    Published: 25 Oct 2016
    7.6
    High

    CVE-2016-8281

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-5536.

    Published: 25 Oct 2016
    8.2
    High

    CVE-2016-8293

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-5530.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-8294

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 25 Oct 2016
    4.3
    Medium

    CVE-2016-8295

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 25 Oct 2016
    7.6
    High

    CVE-2016-8296

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LDAP.

    Published: 25 Oct 2016
    8.8
    High

    CVE-2016-3505

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to JavaServer Faces.

    Published: 25 Oct 2016
    6.1
    Medium

    CVE-2016-5543

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component in Oracle Financial Services Applications 12.0.0 and 12.1.0 allows remote attackers to affect confidentiality and integrity via vectors related to INFRA.

    Published: 25 Oct 2016
    5
    Medium

    CVE-2016-5553

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via unknown vectors.

    Published: 25 Oct 2016
    3.1
    Low

    CVE-2016-5618

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.

    Published: 25 Oct 2016
    7.8
    High

    CVE-2016-1247

    Last Modified: 12 Apr 2025

    The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10, and the nginx ebuild before 1.10.2-r3 on Gentoo allow local users with access to the web server user account to gain root privileges via a symlink attack on the error log.

    Published: 25 Oct 2016
    7
    High

    CVE-2016-5652

    Last Modified: 20 Apr 2025

    An exploitable heap-based buffer overflow exists in the handling of TIFF images in LibTIFF's TIFF2PDF tool. A crafted TIFF document can lead to a heap-based buffer overflow resulting in remote code execution. Vulnerability can be triggered via a saved TIFF file delivered by other means.

    Published: 25 Oct 2016
    8.8
    High

    CVE-2016-5875

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5314. Reason: This candidate is a reservation duplicate of CVE-2016-5314. Notes: All CVE users should reference CVE-2016-5314 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Oct 2016
    8.1
    High

    CVE-2016-8331

    Last Modified: 12 Apr 2025

    An exploitable remote code execution vulnerability exists in the handling of TIFF images in LibTIFF version 4.0.6. A crafted TIFF document can lead to a type confusion vulnerability resulting in remote code execution. This vulnerability can be triggered via a TIFF file delivered to the application using LibTIFF's tag extension functionality.

    Published: 25 Oct 2016
    7.5
    High

    CVE-2016-9391

    Last Modified: 20 Apr 2025

    The jpc_bitstream_getbits function in jpc_bs.c in JasPer before 2.0.10 allows remote attackers to cause a denial of service (assertion failure) via a very large integer.

    Published: 25 Oct 2016