CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-9555

    Last Modified: 12 Apr 2025

    The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows remote attackers to cause a denial of service (out-of-bounds slab access) or possibly have unspecified other impact via crafted SCTP data.

    Published: 25 Oct 2016
    5.5
    Medium

    CVE-2016-9388

    Last Modified: 20 Apr 2025

    The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

    Published: 24 Oct 2016
    7.5
    High

    CVE-2016-8867

    Last Modified: 12 Apr 2025

    Docker Engine 1.12.2 enabled ambient capabilities with misconfigured capability policies. This allowed malicious images to bypass user permissions to access files within the container filesystem or mounted volumes.

    Published: 24 Oct 2016
    7.5
    High

    CVE-2016-9389

    Last Modified: 20 Apr 2025

    The jpc_irct and jpc_iict functions in jpc_mct.c in JasPer before 1.900.14 allow remote attackers to cause a denial of service (assertion failure).

    Published: 24 Oct 2016
    5.5
    Medium

    CVE-2016-9390

    Last Modified: 20 Apr 2025

    The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.

    Published: 24 Oct 2016
    7.5
    High

    CVE-2016-8610

    Last Modified: 20 Apr 2025

    A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

    Published: 24 Oct 2016
    6.4
    Medium

    CVE-2016-8613

    Last Modified: 21 Nov 2024

    A flaw was found in foreman 1.5.1. The remote execution plugin runs commands on hosts over SSH from the Foreman web UI. When a job is submitted that contains HTML tags, the console output shown in the web UI does not escape the output causing any HTML or JavaScript to run in the user's browser. The output of the job is stored, making this a stored XSS vulnerability.

    Published: 24 Oct 2016
    7.8
    High

    CVE-2016-9387

    Last Modified: 20 Apr 2025

    Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified impact via a crafted file, which triggers an assertion failure.

    Published: 23 Oct 2016
    7.8
    High

    CVE-2016-10249

    Last Modified: 20 Apr 2025

    Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.

    Published: 23 Oct 2016
    8.8
    High

    CVE-2016-0241

    Last Modified: 12 Apr 2025

    IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.

    Published: 22 Oct 2016
    3.7
    Low

    CVE-2016-0240

    Last Modified: 12 Apr 2025

    IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by leveraging use of HTTP.

    Published: 22 Oct 2016
    4.3
    Medium

    CVE-2016-0242

    Last Modified: 12 Apr 2025

    IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.

    Published: 22 Oct 2016
    8.8
    High

    CVE-2016-0239

    Last Modified: 12 Apr 2025

    IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors.

    Published: 22 Oct 2016
    6.1
    Medium

    CVE-2016-0246

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 22 Oct 2016
    7.8
    High

    CVE-2016-0247

    Last Modified: 12 Apr 2025

    IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.

    Published: 22 Oct 2016
    8.8
    High

    CVE-2016-0326

    Last Modified: 12 Apr 2025

    IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a crafted "HTML request."

    Published: 22 Oct 2016
    7.8
    High

    CVE-2016-0328

    Last Modified: 12 Apr 2025

    IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.

    Published: 22 Oct 2016
    4.3
    Medium

    CVE-2016-0377

    Last Modified: 12 Apr 2025

    The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 22 Oct 2016
    8.8
    High

    CVE-2016-0236

    Last Modified: 12 Apr 2025

    IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field.

    Published: 21 Oct 2016
    9.8
    Critical

    CVE-2016-7854

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6947, CVE-2016-6948, CVE-2016-6950, CVE-2016-6951, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6959, CVE-2016-6960, CVE-2016-6966, CVE-2016-6970, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, CVE-2016-7019, CVE-2016-7852, and CVE-2016-7853.

    Published: 21 Oct 2016
    9.8
    Critical

    CVE-2016-7852

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6947, CVE-2016-6948, CVE-2016-6950, CVE-2016-6951, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6959, CVE-2016-6960, CVE-2016-6966, CVE-2016-6970, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, CVE-2016-7019, CVE-2016-7853, and CVE-2016-7854.

    Published: 21 Oct 2016
    9.8
    Critical

    CVE-2016-7853

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6940, CVE-2016-6941, CVE-2016-6942, CVE-2016-6943, CVE-2016-6947, CVE-2016-6948, CVE-2016-6950, CVE-2016-6951, CVE-2016-6954, CVE-2016-6955, CVE-2016-6956, CVE-2016-6959, CVE-2016-6960, CVE-2016-6966, CVE-2016-6970, CVE-2016-6972, CVE-2016-6973, CVE-2016-6974, CVE-2016-6975, CVE-2016-6976, CVE-2016-6977, CVE-2016-6978, CVE-2016-6995, CVE-2016-6996, CVE-2016-6997, CVE-2016-6998, CVE-2016-7000, CVE-2016-7001, CVE-2016-7002, CVE-2016-7003, CVE-2016-7004, CVE-2016-7005, CVE-2016-7006, CVE-2016-7007, CVE-2016-7008, CVE-2016-7009, CVE-2016-7010, CVE-2016-7011, CVE-2016-7012, CVE-2016-7013, CVE-2016-7014, CVE-2016-7015, CVE-2016-7016, CVE-2016-7017, CVE-2016-7018, CVE-2016-7019, CVE-2016-7852, and CVE-2016-7854.

    Published: 21 Oct 2016
    7.2
    High

    CVE-2016-1000118

    Last Modified: 12 Apr 2025

    XSS & SQLi in HugeIT slideshow v1.0.4

    Published: 21 Oct 2016
    7.2
    High

    CVE-2016-1000119

    Last Modified: 12 Apr 2025

    SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla

    Published: 21 Oct 2016
    7.2
    High

    CVE-2016-1000115

    Last Modified: 12 Apr 2025

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

    Published: 21 Oct 2016
    7.2
    High

    CVE-2016-1000116

    Last Modified: 12 Apr 2025

    Huge-IT Portfolio Gallery manager v1.1.0 SQL Injection and XSS

    Published: 21 Oct 2016
    7.2
    High

    CVE-2016-1000117

    Last Modified: 12 Apr 2025

    XSS & SQLi in HugeIT slideshow v1.0.4

    Published: 21 Oct 2016
    6
    Medium

    CVE-2016-8910

    Last Modified: 12 Apr 2025

    The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.

    Published: 21 Oct 2016
    7.5
    High

    CVE-2016-10248

    Last Modified: 20 Apr 2025

    The jpc_tsfb_synthesize function in jpc_tsfb.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) via vectors involving an empty sequence.

    Published: 20 Oct 2016
    8.8
    High

    CVE-2016-8866

    Last Modified: 20 Apr 2025

    The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862.

    Published: 20 Oct 2016
    7.5
    High

    CVE-2016-2848

    Last Modified: 12 Apr 2025

    ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.

    Published: 20 Oct 2016
    9.8
    Critical

    CVE-2016-5287

    Last Modified: 21 Nov 2024

    A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

    Published: 20 Oct 2016
    5.9
    Medium

    CVE-2016-5288

    Last Modified: 21 Nov 2024

    Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.

    Published: 20 Oct 2016
    6.5
    Medium

    CVE-2016-8626

    Last Modified: 21 Nov 2024

    A flaw was found in Red Hat Ceph before 0.94.9-8. The way Ceph Object Gateway handles POST object requests permits an authenticated attacker to launch a denial of service attack by sending null or specially crafted POST object requests.

    Published: 20 Oct 2016
    6
    Medium

    CVE-2016-8909

    Last Modified: 12 Apr 2025

    The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.

    Published: 20 Oct 2016
    8.8
    High

    CVE-2016-7071

    Last Modified: 21 Nov 2024

    It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authenticated attacker could use this flaw to execute arbitrary VMs on systems managed by CloudForms if they know the ID of the VM.

    Published: 20 Oct 2016
    4.3
    Medium

    CVE-2016-8283

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote authenticated users to affect availability via vectors related to Server: Types.

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-5629

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.51 and earlier, 5.6.32 and earlier, and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: Federated.

    Published: 19 Oct 2016
    3.1
    Low

    CVE-2016-8286

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.14 and earlier allows remote authenticated users to affect confidentiality via vectors related to Server: Security: Privileges.

    Published: 19 Oct 2016
    3.1
    Low

    CVE-2016-8288

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin.

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-5507

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.32 and earlier and 5.7.14 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.

    Published: 19 Oct 2016
    7.8
    High

    CVE-2016-5617

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-6664. Reason: This candidate is a reservation duplicate of CVE-2016-6664. Notes: All CVE users should reference CVE-2016-6664 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-5634

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to RBR.

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-5635

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: Security: Audit.

    Published: 19 Oct 2016
    6.5
    Medium

    CVE-2016-5609

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML.

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-5630

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.31 and earlier and 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.

    Published: 19 Oct 2016
    5.5
    Medium

    CVE-2016-7440

    Last Modified: 12 Apr 2025

    The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.

    Published: 19 Oct 2016
    5.5
    Medium

    CVE-2016-10058

    Last Modified: 20 Apr 2025

    Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick before 6.9.6-3 allows remote attackers to cause a denial of service (memory consumption) via a crafted image file.

    Published: 19 Oct 2016
    4.9
    Medium

    CVE-2016-3495

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.

    Published: 19 Oct 2016
    4.4
    Medium

    CVE-2016-5584

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.

    Published: 19 Oct 2016